News with an accent.

Two contestants look at a laptop screen in front of the Pwn2Own Ireland sign.
Gadgets

Pwn2Own Ireland: Galaxy S26, Sonos Era 300 and Hue fall

A Pixel 10 held out on day one of the Zero Day Initiative contest; the flaws found in the rest have no public CVE or patch yet.

A Samsung Galaxy S26, a Sonos Era 300 speaker, a Philips Hue Bridge Pro hub and the OpenAI Codex coding assistant were all compromised on Oct. 6, the first day of Pwn2Own Ireland 2026. The contest, where researchers get paid for demonstrating previously unknown ("zero-day") flaws in devices and software, is run by the Zero Day Initiative (ZDI), which published the day's results.

A Google Pixel 10 resisted: the White Noise Club team could not get its attack working within the allotted time. Teams that tried a Brother printer, a Lexmark printer, a Garmin Index BPM and the Chroma tool also came up short.

For people who use those products, the results bring no immediate risk and no action to take. Manufacturers receive the details privately and, according to BleepingComputer, have 90 days to ship a patch before ZDI discloses the technical information. That is why none of these flaws has a CVE identifier, an affected version or a fix yet.

The day's results

A "collision" means the team used, at least in part, bugs that the vendor or someone else already knew about, which is why the prize is smaller. All three attacks on the Galaxy S26 were of that kind. The one by Viettel Cyber Security combined four bugs, and ZDI says the vendor knew three; the one by Interrupt Labs used four, with three collisions and one new flaw.

Day one results at Pwn2Own Ireland 2026
TargetSuccessful attacksFailed attacks
Samsung Galaxy S263 (all with a collision)0
Philips Hue Bridge Pro3 (two with a collision)0
Sonos Era 3002 (one with a collision)0
LiteLLM2 (one with a collision)0
Lexmark CX532adwe21
Garmin Index BPM11
Oracle Autonomous AI Database10
OpenAI Codex10
Google Pixel 1001
Brother MFC-L8970CDW01
Chroma01
Source: Zero Day Initiative

The top prize was 50 000 dollars, won by McCaulay Hudson, who chained an out-of-bounds write with a format string bug to take over a Sonos Era 300. Payouts of 40 000 dollars went to Ikotas Labs for a single argument injection bug in OpenAI Codex, to VinSOC for five bugs in Oracle Autonomous AI Database and for seven new flaws in the Philips Hue Bridge Pro, and to Xint for compromising LiteLLM.

BleepingComputer reports 32 new flaws and 388 500 dollars in prizes, figures that do not match what ZDI's post details, so this report does not use them. The contest continues over the following days, and ZDI will publish the remaining results there.

Keep reading

El Mediático uses cookies to measure its audience and, where advertising is active, to show ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)