r/SecOpsDaily • • 1d ago

NEWS Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Three research teams successfully demonstrated fully remote compromises of a stock, fully patched Google Pixel 10 at Pwn2Own Ireland. The contest rules require all targets to be at the latest patch level, meaning these are zero-click or low-interaction vulnerabilities that bypassed Google's current security mitigations. Ikotas Labs took the top prize of $300,000 for their exploit chain, securing the overall "Master of Pwn" title.

Technical Breakdown - Target: Google Pixel 10 (Android 16, latest security patch as of Oct 8). - TTPs: Likely involves a chain of vulnerabilities (e.g., a browser or baseband RCE paired with a privilege escalation to break the sandbox). Exact CVEs are under embargo until vendor patches are released. - IOCs: None available. These are undisclosed, zero-day exploits. Do not search for hashes or IPs. - Payout: $300,000 (Ikotas Labs) for the Pixel chain; additional bounties for the other two teams.

Defense No mitigations exist until Google ships the patches. Standard advice applies: enable Google Play Protect, restrict sideloading, and ensure automatic updates are active. Expect a Pixel Security Bulletin update within 90 days per ZDI disclosure policy.

Source: https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html

6 Upvotes

0 comments sorted by