Pwn2Own Ireland’s October 7 results recorded three more successful Galaxy S26 exploit demonstrations, following three on October 6. That brought the first two days’ total to six, with separate teams presenting separate entries. The contest was organized by Trend Micro’s Zero Day Initiative (ZDI).
Three more Galaxy S26 demonstrations on October 7
The three October 7 successes came from a team that included Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara; Kyeongmin Kim; and PetoWorks. Their entries used different bug combinations: the Valsamaras team used one Confused Deputy (CWE-441) bug, Kyeongmin Kim used one unique bug and two collisions, and PetoWorks used three collisions.
A collision is a contest classification for a bug that overlaps with another submission. These results describe distinct demonstrations, not a shared exploit chain.
Ikotas’s four-bug chain on October 6
On October 6, Ikotas Labs exploited a Galaxy S26 using four bugs, according to ZDI’s contest results. One was already known to Samsung but remained unpatched at the contest. Ikotas received $11,000 and 4.5 Master of Pwn points for the entry.
The other October 6 successes came from Viettel Cyber Security and Interrupt Labs. Viettel used four bugs, three of them already known to Samsung. Interrupt Labs used four bugs: three collisions and one zero-day. A zero-day is a software flaw exploited before a fix is available.
Ikotas’s claim about a single email
On October 1, Ikotas CEO Satoki Tsuji said a single email could trigger remote code execution (RCE) on a Galaxy S26. RCE means running code on a device from afar. ZDI’s October 6 results record Ikotas’s successful demonstration and four-bug chain.