Three Zero-Day Exploits Compromise Samsung Galaxy S26 at Pwn2Own Ireland 2026
Security researchers earn cash awards during second day of competition

Key Takeaways
- Three zero-day vulnerabilities were exploited against Samsung Galaxy S26 devices during Pwn2Own Ireland 2026.
- The exploits were part of a larger event where 45 unique zero-days were leveraged across multiple platforms.
- Cash awards totaling $232,500 were distributed to researchers for successful exploits during the second day.
- Specific CVEs, exploit details, and patch information have not been publicly released.
- Responsible disclosure and coordination between researchers, Samsung, and organizers is expected.
Quick answers
- What happened?
- On the second day of Pwn2Own Ireland 2026, security researchers exploited three zero-day vulnerabilities on Samsung Galaxy S26 devices, earning cash awards as part of a broader effort that saw 45 unique zero-days exploited across the event. The specific CVEs and exploit details have not been publicly disclosed.
- Which products are affected?
- Samsung Galaxy S26
- What should defenders do?
- Users should ensure their Samsung Galaxy S26 devices are running the latest available software updates. Samsung and security researchers typically coordinate responsible disclosure, and patches are released once vulnerabilities are confirmed and advisory information is published. Monitoring official Samsung security advisories and applying updates promptly is recommended.
During the second day of Pwn2Own Ireland 2026, security researchers successfully exploited three zero-day vulnerabilities affecting Samsung Galaxy S26 smartphones. The exploits contributed to a total of $232,500 in cash awards distributed to researchers across the event, which also featured the exploitation of 45 unique zero-day vulnerabilities targeting various platforms. BleepingComputer reported that the Galaxy S26 compromises were part of the day's activity, though specific vulnerability details, CVE identifiers, and technical particulars were not disclosed in the initial report. Samsung and event organizers are likely coordinating responsible disclosure processes, as is typical for Pwn2Own participants. The full scope of affected systems, exact exploit methodologies, and patch timelines remain unconfirmed and pending official advisories.
Security Details
Three zero-day vulnerabilities were exploited on Samsung Galaxy S26 devices during the Pwn2Own Ireland 2026 event. Specific CVE identifiers, exploit chains, and technical details have not been disclosed in public reports.
Affected products
Samsung Galaxy S26
Mitigation
Users should ensure their Samsung Galaxy S26 devices are running the latest available software updates. Samsung and security researchers typically coordinate responsible disclosure, and patches are released once vulnerabilities are confirmed and advisory information is published. Monitoring official Samsung security advisories and applying updates promptly is recommended.
Sources
BleepingComputer
Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
Oct 8, 2026 · 06:32
Original link
Related Security News

LibreOffice and OpenOffice Java Flaw Enables Silent Code Execution via Malicious Spreadsheets
Security researchers have demonstrated a proof-of-concept attack affecting LibreOffice and Apache OpenOffice that allows malicious spreadsheets to execute attacker code upon file opening without triggering the macro warnings typically displayed by the applications. The vulnerability requires Java support to be enabled within the office suites to function.




