Three teams demonstrate remote Pixel 10 attacks at security contest
Source announcement and demonstrations: 8 October 2026
Three teams successfully demonstrated remote attacks against a Google Pixel 10 during the third day of Pwn2Own Ireland on 8 October. The Zero Day Initiative, which runs the supervised contest, recorded three separate successful attempts. One team combined multiple weaknesses; another used a two-bug chain that included a newly found flaw. The organiser had not published full technical instructions or vendor fixes in its day-three results.
The contest requires researchers to demonstrate an attack under set conditions and report the weaknesses through its process. A successful demonstration is meaningful evidence that a particular route worked in that setting. It does not show that criminals are using the same route against Pixel owners, or that every Pixel 10 can be compromised in ordinary use. Some contest entries also overlap with bugs already known to organisers, which is why the public results distinguish new findings from “collisions”.
Phones carry messages, photographs, banking apps and work accounts, so weaknesses that let someone move from a remote entry point towards deeper access deserve attention. At present, the public results do not establish which apps or user actions, if any, were needed for each Pixel attempt. That detail matters when judging personal risk.
Pixel 10 owners should keep automatic system and app updates enabled and install Google’s official fixes when released. Businesses managing these phones can monitor vendor security notices and their device-management inventory. There is no reason in these contest results alone to claim that all Pixel users have been attacked.






Comments