LiMP VPN
← All news

Fully Patched Pixel 10 Hacked Three Times in One Day

Fully Patched Pixel 10 Hacked Three Times in One Day

In short: at the Pwn2Own Ireland 2026 hacking contest in Cork, three independent research teams remotely hacked a Google Pixel 10 — a phone running every available security patch. Organizer Zero Day Initiative (ZDI, part of Trend Micro) paid out $562,500 combined for the three successful attacks, and the top team walked away with the Master of Pwn title. The reminder: even a fully updated device isn't safe from zero-day flaws the vendor doesn't know about yet.

What happened

Pwn2Own Ireland 2026 ran October 6–9. Zero Day Initiative runs the contest every year, bringing together security researchers who find and demonstrate new vulnerabilities in mainstream devices for cash prizes. On day three, October 8, the Google Pixel 10 became the event's single most expensive target. For more on why these contests matter and what they say about real-world device security, see our broader look at mobile device threats.

The contest's "remote" category requires compromising the phone either by browsing to a web page in the default browser or via Wi-Fi, Bluetooth, NFC, or the baseband modem — no physical access, no USB. All three teams used exactly that vector.

Three teams, three different bug chains

Ikotas Labs chained several bugs together and took home $300,000 — the contest's top prize and the Master of Pwn title. Researchers Tim Becker and Yves Bieri, competing as Xint, used a single bug, but part of their finding was already known to the vendor, so their payout was reduced to $150,000. The third team — Dimitrios Valsamaras and Ken Gannon (Djini.ai) with Tenia Valsamara (Mobile Hacking Lab, CENSUS Labs) — combined a fresh zero-day with an already-known flaw and earned $112,500.

Together, the three working attacks on the same, fully patched phone earned researchers $562,500 — more than any other single target at the event. The same contest also saw Samsung's Galaxy S26 hacked multiple times, and over the three days, Pwn2Own Ireland 2026 paid out more than $1.2 million in total prizes.

Why patches didn't help

The key detail is that the Pixel 10 at the contest was running the security patch level current as of the event date — meaning a user who diligently updates their phone still wouldn't have been protected against these specific attacks. The reason is simple: updates close vulnerabilities the vendor already knows about, while Pwn2Own exists to surface zero-days — flaws Google hadn't discovered yet. A patch, by definition, can't do anything about a problem the vendor doesn't know exists.

That's not an argument against updating — regular patches still close every vulnerability that has become known, including ones found at past Pwn2Own events. But it does mean "I updated my phone, so I'm safe" is a dangerous oversimplification: some risk always sits beyond the edge of what the vendor currently knows.

What happens to the vulnerabilities now

Under Pwn2Own rules, every bug found is disclosed to the vendor privately, and Google has 90 days to ship a fix before technical details can go public. As of this writing, there's no evidence these specific flaws have been used against real-world users — the risk remains theoretical for now, but it stops being theoretical the moment technical details leak beyond the narrow circle of the vendor and the researchers who found them.

What this means for everyday users

You should still install updates: they won't stop a zero-day, but they close dozens of already-known holes that real attackers do exploit at scale. And since one of the contest's permitted attack vectors is compromise over a Wi-Fi connection, it's worth paying closer attention to the network layer specifically — avoid joining random open access points without reason, and encrypt your traffic on networks you don't fully trust. The LiMP VPN app for Android encrypts the connection between your device and the internet and hides its contents from the public network's owner or your ISP — it won't patch flaws in the OS itself and won't stop a browser- or NFC-based attack, but it removes one path an attacker could use to reach your phone over an untrusted network.

Plans from 69 ₽/month, a verified no-logs policy: LiMP VPN pricing.

Sources