As reported by The Hacker News, three research teams successfully demonstrated remote exploits against a fully patched Google Pixel 10 at Pwn2Own Ireland on October 8, 2026, collectively earning $562,500. Ikotas Labs took the top prize of $300,000 and overall contest winner status.

Security Impact: As reported by The Hacker News, three research teams successfully demonstrated remote exploits against a fully patched Google Pixel 10 at Pwn2Own Ireland on October 8, 2026, collectively earning $562,500.

While Pwn2Own events are a regular fixture in offensive security, this particular batch of results deserves close attention from enterprise mobile defenders for several reasons — and none of them are about the prize money.

Why This Matters

The most significant takeaway is that three independent teams reached full remote code execution or sensitive data extraction on a fully patched, flagship Android device. That is not a single researcher finding an obscure edge case — it is convergent validation that the current mobile attack surface remains deeply exploitable even on Google's most hardened hardware.

All three entries were registered as remote exploits, meaning they required no physical access to the device. Under Pwn2Own rules, that means the attack vector was one of: browser-based web content, NFC, Wi-Fi, Bluetooth, or baseband. This is the threat model that matters most for enterprise mobile fleets where devices are constantly in users' hands, not behind corporate firewalls.

It is also worth noting that at least two of the three entries involved collisions — bugs that were already known to the vendor or organizer before the contest. This suggests Google may already have some of these issues in its remediation pipeline, but the fact that they remained unpatched on a fully updated device as of October 8 indicates the patch cycle has not yet caught up.

Who Is at Risk

The 90-day disclosure clock is now ticking. Once ZDI publishes full technical details, these exploit chains become available to the broader research community — and potentially to threat actors who can adapt them.

Organizations most exposed include:

Who Is at Risk
BYOD and corporate-issued Android fleets running Pixel or similar devices, especially in regulated industries
Mobile-first workforces where phones are the primary computing device and may access sensitive corporate resources
High-value individuals — executives, government personnel, journalists — who are realistic targets for targeted mobile exploits
MDM/UEM administrators who need to plan for emergency patch deployment once fixes land

What Defenders Should Do Now

No patch is available yet. Google's October 2026 Pixel Update was published October 6 — two days before the contest — and does not address these issues. ZDI has not published technical details and will not for up to 90 days pending vendor remediation. That means defenders are in a blind mitigation window.

Shield53 Recommendations

  • Inventory Pixel 10 and Pixel-class devices across your fleet immediately. Know who has them and what data they access.
  • Reduce attack surface now: Disable NFC, Bluetooth, and Wi-Fi when not actively needed on high-risk users' devices. This narrows the remote attack vectors identified under Pwn2Own rules.
  • Strengthen browser isolation on managed mobile devices. If your MDM supports managed browser configurations with enhanced isolation, enable them. Web content delivery is one of the confirmed remote vectors.
  • Prepare emergency patch deployment: Configure your UEM/MDM platform to push the next Google security update as soon as it is released. Do not wait for the standard monthly cycle if an out-of-band patch drops.
  • Monitor for targeted mobile activity: If you operate a mobile threat defense (MTD) solution, ensure detection rules are current. If you do not, this is a strong argument for evaluating one.
  • Brief high-risk personnel: Executives and other targeted individuals should be advised to avoid opening unexpected links and to keep devices powered and updated.

Broader Implications

The fact that multiple teams independently found viable exploit chains on the same device in the same week suggests the mobile attack surface is not shrinking as fast as vendors' hardening efforts might suggest. Baseband and radio interface vulnerabilities, in particular, remain a persistent concern because they operate below the OS layer where most mobile security tooling has visibility.

For CISOs, this is a reminder that mobile devices are not accessories to the security program — they are endpoints in every meaningful sense. The post-90-day window, when full exploit details become public, is when the real risk materializes for organizations that have not prepared.

The teams at Pwn2Own have done the defensive community a service. The question now is whether defenders will use the head start.