The results of three days of Pwn2Own Ireland 2026 competitions have been summarized, during which 42 successful attacks utilizing previously unknown vulnerabilities (0-day) were demonstrated on smartphones, smart home devices, printers, and AI tools. The attacks were conducted using the latest firmware and operating systems with all available updates and in default configurations. The prize pool amounted to $1.33 million.
Executed attacks:
- Samsung Galaxy S26 smartphone: 6 successful hacks. Rewards paid: $31,250, $15,750, $11,000, $8,500, and $6,250.
- Google Pixel 10 smartphone: 1 successful hack. Reward paid: $150,000.
- Home automation device Home Assistant Green: 6 successful hacks. Rewards paid: $30,000, $12,000, $7,500, $7,000, $4,750, and $4,500.
- Philips Hue Bridge Pro smart lights: 4 successful hacks. Rewards paid: $40,000, $12,000, $6,000, and $5,000.
- Garmin Index BPM blood pressure monitor: 2 successful hacks using vulnerabilities related to buffer overflow. Rewards paid: $20,000 and $6,750.
- Sonos Era 300 smart speakers: 5 successful hacks using vulnerabilities related to buffer overflow and string formatting errors. Rewards paid: $50,000, $17,500, $12,500, $10,500, and $9,500.
- Lexmark CX532adw printer: 5 successful hacks using vulnerabilities related to memory access after free. Rewards paid: $20,000, $10,000, $5,000, $5,000, and $4,250.
- Canon imageFORCE 1643F printer: 1 successful hack using vulnerabilities related to insufficient authentication, command injection, and hardcoded credentials. Reward paid: $10,000.
- Brother MFC-L8970CDW printer: 1 successful hack. Reward paid:
$20000. - LiteLLM AI gateway: 2 successful hacks using vulnerabilities related to improper input validation and code injection. Rewards paid: $40,000 and $15,000.
- Oracle Autonomous AI Database management automation system: 5 successful hacks related to memory access after free and type confusion handling errors. Rewards paid: $40,000, $14,000, $10,000, $6,250, and $6,000.
- OpenAI Codex AI agent: 1 successful hack using vulnerabilities related to argument injection. Reward paid: $40,000.
- Dynamo AI platform: 1 successful hack using a buffer overflow vulnerability. Reward paid: $40,000.
- Chroma vector database: 2 successful hacks. Rewards paid: $12,000 and $4,500.
In addition to the successful attacks mentioned above, 9 attempts to exploit vulnerabilities were unsuccessful, in all cases because the teams could not complete the attack within the limited time allotted.
The attempts to hack the Brother MFC-L8970CDW printers and
Lexmark CX532adwe, the Garmin Index BPM blood pressure monitor, the Google Pixel 10 smartphone, the Chroma database, and the Home Assistant Green home automation system were unsuccessful.
The specific components affected have not yet been disclosed. According to the competition rules, detailed information about all demonstrated 0-day vulnerabilities will be published only after 90 days, which are given to manufacturers to prepare updates that address the vulnerabilities.
Source: opennet.ru
