Yaamlabs

Vulnerabilities

Pwn2Own Ireland 2026: phones, smart homes and Codex fall

Pwn2Own Ireland paid $388,500 for 32 zero-days on day one. What was hacked, when fixes are due, and what to do now for phones, IoT and AI tools.

Pwn2Own Ireland 2026 opened in Cork on October 6. By the end of the first day, the Zero Day Initiative (ZDI), which runs the contest, had paid $388,500 for 32 unique zero-days. ZDI logged three successful entries against the Samsung Galaxy S26 (BleepingComputer counts two), along with a Sonos Era 300 speaker, a Philips Hue Bridge Pro, a Lexmark office printer, the LiteLLM AI gateway, Oracle Autonomous AI Database and OpenAI's Codex coding agent. Day two had 24 attempts on the schedule with roughly $780,000 on offer, and the contest runs until October 9, so figures here are as of October 8.

These are contest zero-days, not attacks in the wild: no exploitation outside the contest has been reported. If your staff carry Galaxy phones, your offices have smart speakers or hubs, or your developers use AI coding agents, these products have working exploits and no public fix yet. You cannot patch them this week, but you can shrink who can reach them.

How the contest works

Each team gets a fixed time slot to exploit a fully updated target live. The phone rules are realistic: a remote entry "must compromise the device by browsing to web content in the default browser", so the victim only has to open a page. For coding agents, ZDI launches the agent inside a repository the contestant controls and that has not been granted trust. The exploit has to fire before or during the trust prompt and end with code running outside the agent's sandbox.

When part of a chain was already known to ZDI or the vendor, the entry counts as a "collision" and pays less. Ikotas Labs' Galaxy S26 chain on day one used a bug that ZDI described as known to the vendor "yet unpatched", so some of these holes were known and still open in shipping firmware.

What fell on days one and two

On day one, ZDI logged 15 successes in 20 attempts. McCaulay Hudson took the Sonos Era 300 with an out-of-bounds write and a format string bug for $50,000. VinSOC used seven zero-days against the Philips Hue Bridge Pro and five more against Oracle Autonomous AI Database, $40,000 each. Taisic Yun of Xint got a reverse shell on LiteLLM by combining improper input validation with code injection, also for $40,000. Each of the three Galaxy S26 chains used four bugs, most of them collisions.

Ikotas Labs needed a single argument injection bug to compromise OpenAI Codex, worth $40,000. Argument injection means attacker-controlled text ends up as an option on a command the tool runs. ZDI has not published the affected Codex versions or a CVE ID. The Google Pixel 10 attempt by White Noise Club ran out of time, with three more remote Pixel 10 attempts scheduled for October 8. Claude Code, the other coding agent in the rules, and the Apple iPhone 17 had no attempt on the published schedule.

ZDI's day-two results list the Galaxy S26 compromised three more times, starting with a single confused deputy bug (CWE-441) from Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara. A confused deputy is a privileged component tricked into acting for a caller that lacks that right. Home Assistant Green fell several times, first to Yves Bieri of Xint for $30,000, and the Sonos Era 300 fell again. Dynamo, Oracle Autonomous AI Database and Chroma, which had held on day one, were also compromised, and the Brother MFC-L8970CDW printer held for a second day. ZDI had not posted a day-two total at the time of writing.

When the fixes arrive

ZDI buys each winning exploit and passes it privately to the vendor. Press coverage, including BleepingComputer, says vendors get 90 days to release fixes before ZDI publishes. ZDI's own FAQ gives 120 days from first notification as its standard deadline and says Pwn2Own bugs go through that standard process, so the exact clock is not settled in public sources. Counting from October 6, 90 days ends on January 4, 2027 and 120 days on February 3, 2027.

If a vendor misses the deadline, ZDI's disclosure policy says it publishes a limited advisory with mitigations. Bugs that collided with known issues may be fixed sooner, because the vendor already knew about them. Either way, plan on these products staying unfixed through the end of the year.

What to do

Phones

The remote phone category starts from a web page in the default browser, and until Samsung ships fixes the only defence is making sure updates land quickly. In your mobile device management (MDM) tool, set a minimum Android security patch level for any phone that reaches company email or files, and block devices that fall behind. Watch Samsung's monthly security bulletins for fixes credited to ZDI and push them the day they appear.

Smart home devices in offices

The Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green turn up in meeting rooms. Put them on their own VLAN or guest SSID with no route to corporate subnets, so a compromised speaker is not a foothold. Do not forward Home Assistant's web interface (TCP 8123 by default) to the internet; reach it over a VPN instead. Turn on automatic updates on each device so the fix installs when it ships.

Printers

Two of the three printer models fell: the Lexmark CX532adwe on both days and the Canon imageFORCE 1643F on day two. Restrict each printer's web management interface to admin workstations at the switch or firewall, leave only the print ports users need (TCP 9100 and IPP on 631) open from user VLANs, and confirm no printer is reachable from the internet. Install the firmware fixes when they appear.

AI coding agents and AI infrastructure

The Codex rule set is the scenario to plan around: a developer opens an untrusted repository and the agent runs code before anyone approves anything. Run coding agents in a container or devcontainer with no production credentials, give them short-lived tokens, and have developers clone unfamiliar repositories into that sandbox, not their main workstation. ZDI has not said which Codex component was hit, so keep the CLI and IDE extensions on their latest release.

LiteLLM, Chroma, Dynamo and Postgres pgvector, all targets this year, are often stood up by data teams outside change control. Find every instance, keep it off the internet, put authentication in front of it and add it to your patch list. A LiteLLM proxy holds the API keys for every model provider it fronts, so treat a compromise as a key rotation event.

How to check

There are no indicators of compromise to hunt for, because the exploits have not been used outside the contest and the details are private. No network attached storage (NAS) device is on this year's target list. List which affected models you own, where they sit on the network and who owns each, then check ZDI's upcoming advisories page every week. Each entry there shows the vendor, CVSS score, report date and disclosure deadline, and moves to the published list once a fix is out.

The wider lesson

Phones go through MDM, but the speakers, hubs, printers and self-hosted AI tools hacked this week often have no owner and no update process. The contest results are a dated list of products with working exploits, and comparing it with your asset inventory shows where those gaps are.

Our attack surface management work keeps a current inventory of what you expose, and our network penetration tests check whether a compromised printer or smart speaker could reach anything that matters. For AI coding agents and LLM gateways, see AI-native systems. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: ZDI Pwn2Own Ireland 2026 day one results, ZDI day two results, ZDI full schedule, Pwn2Own Ireland 2026 rules, ZDI FAQ, ZDI disclosure policy, ZDI upcoming advisories, BleepingComputer, CyberInsider, Cybersecurity News, Infosecurity Magazine.

Back to the blog, or read this post on the full site.