32 Unique 0-Days Exploited in Samsung S26, Pixel 10, OpenAI Codex and Other Devices in Pwn2Own 2026
Pwn2Own Ireland 2026 day one produced 32 unique zero-days against Samsung S26, OpenAI Codex, LiteLLM, and smart devices, paying $388,500.
Researchers demonstrated 32 unique zero-day vulnerabilities on day one of Pwn2Own Ireland 2026, earning $388,500 across phones, smart devices, printers, and AI infrastructure. Ikotas Labs exploited OpenAI Codex via a single argument injection flaw for $40,000, while Taisic Yun obtained a reverse shell on LiteLLM through improper input validation plus code injection. Three teams exploited the Samsung Galaxy S26 with four-bug chains, and VinSOC chained five flaws against Oracle Autonomous AI Database and seven zero-days on Philips Hue Bridge Pro. A Google Pixel 10 attempt failed within the time limit; ZDI emphasized contest demonstrations do not imply real-user attacks.
- 32 unique zero-days demonstrated with $388,500 awarded on day one
- Ikotas Labs exploited OpenAI Codex argument injection flaw for $40,000
- LiteLLM yielded a reverse shell via input validation and code injection chain
- VinSOC disclosed seven zero-days exploiting Philips Hue Bridge Pro
- Samsung Galaxy S26 fell to three teams using four-bug chains
Full article624 words · extracted from cybersecuritynews.com · click to collapse
Security researchers reportedly exploited 32 unique zero-day vulnerabilities and earned $388,500 on the opening day of Pwn2Own Ireland 2026. Samsung Galaxy S26, OpenAI Codex, smart home devices and AI services fell to working exploits, but the Google Pixel 10 attempt failed within the contest time limit.
— TrendAI Zero Day Initiative (@thezdi) October 6, 2026Day 1 is officially wrapped with quite a pot of gold being awarded across the teams! Checkout a snapshot of where the leaderboard stands as of today – more to come over the next two days so keep following along as we post live updates! #Pwn2Own #Pwn2OwnIreland
For full… pic.twitter.com/b7TNYrOQIK
The October 6 results show how security gaps span phones, connected devices, and the software used to build AI systems. ZDI announced 21 entries for day one, with several successful attacks combining new flaws with bugs vendors already knew about.
Samsung Galaxy S26 Exploit chains
Three teams successfully exploited the Samsung Galaxy S26, according to ZDI’s official results. Each used four bugs, but their payouts differed because parts of their exploit chains overlapped with previously reported flaws.
Nguyen Thanh Dat of Viettel Cyber Security earned $31,250 after using one new bug alongside three vendor-known flaws. Interrupt Labs received $15,750 for another chain containing one zero-day and three collisions. Ikotas Labs earned $11,000 after using three new bugs and one flaw Samsung already knew about but had not patched.
These results highlight an important distinction: a successful exploit does not mean every bug in its chain is new. ZDI marks overlapping discoveries as collisions, while still recognizing working attacks and awarding reduced prizes.
The Pixel 10 result was different. White Noise Club researchers Mikhail Evdokimov, Polina Smirnova and Mate Zombor could not complete their exploit within the allotted time. The published result does not establish that the phone has no vulnerabilities.
Ikotas Labs exploited OpenAI Codex using a single argument injection flaw, earning $40,000. ZDI identified the bug type but did not publish the full exploit steps, affected versions, or a CVE identifier in its day-one report.
Taisic Yun of Xint combined improper input validation with code injection to obtain a reverse shell on LiteLLM, earning another $40,000. A reverse shell gives the researcher a command connection back from the targeted system, demonstrating access beyond a simple application error.
Out of Bounds also exploited LiteLLM through four bugs, two previously known, receiving $15,000. Meanwhile, VinSOC chained five flaws against Oracle Autonomous AI Database for $40,000. Its separate attempt against Chroma did not succeed before time expired.
Smart Devices and Printer Flaws
VinSOC researchers Vũ Chí Thành and Huỳnh Đức Tin disclosed seven zero-days while exploiting Philips Hue Bridge Pro, earning $40,000. Other successful Hue attempts contained mostly known bugs, showing why the number of exploited flaws and the number of unique discoveries must remain separate.
McCaulay Hudson earned $50,000 by combining an out-of-bounds write with a format string flaw against Sonos Era 300. These bug classes involve unsafe memory access or unsafe handling of formatted text, although ZDI withheld detailed exploit mechanics.
Lexmark CX532adwe fell to separate attacks from Thanh Do of Team Confused and Sina Kheirkhah of Summoning Team. Interrupt Labs also earned $20,000 by combining an out-of-bounds read and write against Garmin Index BPM.
The demonstrations took place under contest rules; they are not evidence of attacks against real users.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.