Ikotas Labs reportedly used an email to trigger remote code execution on a Samsung Galaxy S26 during Pwn2Own Ireland 2026, without user interaction. The contest took place in Cork, Ireland, from October 6 to 8; the demonstration was reported on October 9.
The reported Galaxy S26 email exploit
The reported demonstration involved remote code execution: running code on a device from another system. Its stated setting was Pwn2Own Ireland, a security contest.
What the reported exploit chain involved
The reported chain combined four flaws. One was reportedly already known to Samsung; three others were described as zero-days, vulnerabilities not previously known to the vendor.
A separate Galaxy S26 result at Pwn2Own
The Trend Micro Zero Day Initiative (ZDI) recorded a separate Galaxy S26 exploit by BunkyoWesterns on October 8. That remote exploit used a two-bug chain: one collision, a flaw already known to a vendor or contest organizer, and one unique bug. ZDI listed an $8,250 award and 3.75 points for BunkyoWesterns’ entry.