Ikotas Labs reportedly used an email to trigger remote code execution on a Samsung Galaxy S26 during Pwn2Own Ireland 2026, without user interaction. The contest took place in Cork, Ireland, from October 6 to 8; the demonstration was reported on October 9.

The reported Galaxy S26 email exploit

The reported demonstration involved remote code execution: running code on a device from another system. Its stated setting was Pwn2Own Ireland, a security contest.

What the reported exploit chain involved

The reported chain combined four flaws. One was reportedly already known to Samsung; three others were described as zero-days, vulnerabilities not previously known to the vendor.

A separate Galaxy S26 result at Pwn2Own

The Trend Micro Zero Day Initiative (ZDI) recorded a separate Galaxy S26 exploit by BunkyoWesterns on October 8. That remote exploit used a two-bug chain: one collision, a flaw already known to a vendor or contest organizer, and one unique bug. ZDI listed an $8,250 award and 3.75 points for BunkyoWesterns’ entry.