Pwn2Own Ireland — Researchers Exploit 98 Zero-Day Vulnerabilities Across Mobile and AI Infrastructure
Publication date: October 9, 2026
Category: News
Introduction
The 2026 Pwn2Own Ireland ethical hacking competition has officially concluded, setting a new benchmark in the exposure and demonstration of unknown security flaws. Over three days of intense competition, 29 international research teams successfully demonstrated 98 zero-day vulnerabilities, collecting a cumulative total of $1,262,000 in cash rewards. Organized by Trend Micro’s Zero Day Initiative (ZDI), this year’s contest targeted products across seven key technology categories, including high-end mobile devices, artificial intelligence infrastructure, AI-powered coding applications, messaging software, smart home devices, printers, and a novel category focused on wellness healthcare devices.
What is Pwn2Own Ireland? (General Analysis)
Pwn2Own is an internationally recognized offensive cybersecurity competition designed to uncover and responsibly disclose software and hardware flaws before malicious actors can weaponize them in the wild. The competition rules mandate that all participating products run their latest available firmware and software versions, requiring contestants to achieve arbitrary code execution through the successful exploitation and chaining of multiple vulnerabilities.
Because the event encompasses numerous independent targets, the specific flaws discovered are not cataloged under a single unified CVE, but rather represent dozens of distinct attack vectors ranging from memory corruption in mobile operating systems to logical flaws in autonomous AI database application programming interfaces (APIs).
- Estimated CVSS Vector (average for remote/local mobile exploitation): CVSS v3.1 8.8 (High) to 9.8 (Critical).
- Predominant CWE Classification (reasoned estimation): CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-20 (Improper Input Validation).
How Does It Work? (Technical Analysis)
Exploiting modern hardened devices in a controlled environment like Pwn2Own requires advanced reverse-engineering methodologies and the development of complex exploit chains. Throughout the tournament, researchers broke down targeted components via structured approaches:
- Initial Entry and Vectorization: Contestants leveraged varied initial access vectors, including short-range wireless interfaces, malformed media file processing (such as flawed image or video codecs), and interactions with exposed services in AI applications and autonomous databases.
- Memory Corruption and Privilege Escalation: To compromise heavily hardened operating systems such as those on the Samsung Galaxy S26 and Google Pixel 10, researchers had to bypass modern mitigation mechanisms (including ASLR, DEP, and control flow integrity). This was achieved through buffer overflow flaws or use-after-free conditions, enabling transition from sandboxed execution to root or kernel-level control.
- Exploit Chaining: The pinnacle of the event occurred on the final day, when researchers secured the competition’s top reward of $300,000 after chaining multiple zero-days to fully compromise the Google Pixel 10.
Affected Systems / Environments
The scope of devices and platforms compromised during the tournament spanned a broad technological footprint:
- High-End Mobile Devices: Samsung Galaxy S26 and Google Pixel 10 (with multiple successful compromises recorded across the three-day event).
- AI Infrastructure and Applications: Oracle Autonomous AI Database and OpenAI Codex.
- Other Target Categories: Messaging applications, smart home automation devices, connected printers, and wellness/healthcare hardware.
Mitigation and Detection
Remediation
- Coordinated Disclosure and Patch Timelines: In accordance with Zero Day Initiative rules, vendors are bound by a strict 90-day disclosure window to develop, test, and deploy security patches before technical details are released publicly.
- Firmware Updates: System administrators and end-users must promptly apply security updates and firmware patches provided by manufacturers as soon as they become available.
- AI Environment Hardening: Isolate autonomous databases and code development tools using network segmentation and strict least-privilege access policies.
Detection
Incident response teams (Blue Teams) should maintain proactive vigilance over execution logs to detect anomalous behavior in critical system processes and unexpected system calls.
{
"detection_rule_name": "Pwn2Own_ZeroDay_Indicator_Monitoring",
"description": "Monitoring for anomalous behavior in mobile processes and AI database services indicative of exploitation attempts.",
"indicators": {
"process_anomaly": "Unexpected spawning of shell processes from media processing Daemons",
"network_activity": "Unusual outbound connections from autonomous database management utilities"
}
}“The mass demonstration of 98 zero-day vulnerabilities highlights that the attack surface within mobile ecosystems and artificial intelligence infrastructure continues to expand faster than traditional secure development lifecycles can secure them.”
Wrapping Up
The Pwn2Own Ireland 2026 event underscored both the resilience and the persistent vulnerabilities inherent in modern hardware and software ecosystems. With 98 zero-days exposed and over $1.2 million distributed in incentives, the competition demonstrates that proactive offensive research remains indispensable in compelling manufacturers to close critical security gaps before threat actors exploit comparable weaknesses in enterprise and consumer environments.
References
- BleepingComputer. (2026, October 9). Hackers earn $1,262,000 for 98 zero-days at Pwn2Own Ireland. BleepingComputer. https://www.bleepingcomputer.com/news/security/hackers-earn-1262000-for-98-zero-days-at-pwn2own-ireland/