Pwn2Own teams remotely compromise fully patched Pixel 10 phones

Three research teams demonstrated remote compromises of fully patched Google Pixel 10 phones on October 8 during Pwn2Own Ireland in Cork. The three successful entries earned a combined $562,500, with Ikotas Labs taking $300,000 and 30 points for a chain of multiple issues. Trend Micro’s Zero Day Initiative, which runs the contest, named Ikotas Labs Master of Pwn after its results gave the team four wins worth $361,000 and 42.5 points.
Pwn2Own requires targets to be fully patched and pays researchers for working exploit demonstrations before passing the vulnerability information to affected vendors. The Pixel 10 results show that current patch status does not eliminate the value of coordinated vulnerability research or the possibility of undisclosed flaws.
Three Pixel 10 remote exploit demonstrations
All three winning Pixel entries were registered in the remote category. Under the contest rules, that category covers attacks delivered through web content opened in the default browser or through NFC, Wi-Fi, Bluetooth, or baseband. To win, an entry must either execute code chosen by the attacker on the phone or obtain sensitive information from it.
ZDI had not published the individual delivery routes, exploit mechanics, or on-device effects as of October 9. Three of four remote attempts against the Pixel 10 succeeded; the remaining attempt, made on the first contest day, ran out of time. The results therefore establish successful demonstrations on contest devices, but do not establish which remote interface each team used.
Xint, represented by Tim Becker and Yves Bieri, used what ZDI described as a single bug collision and received $150,000 and 15 points. Ikotas Labs went next, received the full listed prize of $300,000 and 30 points, and was also labelled a collision in the posted results. Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara used a two-bug chain involving one collision and one zero-day, earning $112,500 and 22.5 points.
Known-bug collisions complicate the results
Pwn2Own rules normally require flaws unknown to both the vendor and the organizer. ZDI calls an entry using a bug already known to either party a collision, and such entries may be accepted for a reduced award. ZDI did not explain why the Ikotas Labs Pixel entry carried a collision label while receiving the full $300,000 prize.
The contest produced similar results for Samsung’s Galaxy S26, where all seven attempts succeeded and six winning entries included at least one collision. ZDI said one flaw in the first-day Galaxy S26 chain from Ikotas Labs was already known to the vendor but remained unpatched. The broader contest outcome also matters because Google Chrome fixes and SaaS DNS attacks tracks Google’s Chrome vulnerability response alongside attacks affecting SaaS and DNS services.
Patch process and operational response
Winning teams submit their exploit material and write-ups to ZDI, which passes the bugs to vendors. Trend Micro’s enterprise security business, TrendAI, has said vendors have 90 days to issue patches before ZDI releases full technical details. Google’s October Pixel bulletin was published on October 6, two days before the demonstrations, and did not mention the contest; ZDI listed neither a fix nor a specific action for Pixel owners.
Separately, Google patched Pixel modem vulnerability CVE-2026-58704 in September and said it may be under limited, targeted exploitation. Google said Pixel phones at patch level 2026-09-05 or later contain that fix. For businesses, the practical implication is to maintain patch-level inventory for managed Pixel devices, deploy Google security updates promptly, and reassess exposure when vendor fixes for the Pwn2Own findings become available.

