Google Pixel 10 Hacked Three Times at Pwn2Own for $562,500, and No Patch Is Out Yet
Three teams of security researchers remotely hacked a fully patched Google Pixel 10 at Pwn2Own Ireland 2026 on Thursday, October 8, earning $562,500 between them. Google has not released a fix yet, so no Pixel 10 owner in the US or anywhere else has a patch to install today.
- Event: Pwn2Own Ireland 2026 in Cork, run by Trend Micro's Zero Day Initiative (ZDI)
- Phone: Google Pixel 10, fully patched, as the contest rules require
- Result: 3 successful remote exploits on October 8, after one failed attempt on October 6
- Prize money for the Pixel 10: $562,500
- Patch status: no fix and no Google statement as of October 9

Who hacked the Google Pixel 10, and for how much?
ZDI's official day-three results list three wins against the Pixel 10. ZDI marked all three as "collisions", meaning at least part of each exploit used a bug that was already known.
| Team | What ZDI recorded | Prize | Master of Pwn points |
|---|---|---|---|
| Xint (Tim Becker, Yves Bieri) | Remote exploit, single bug collision | $150,000 | 15 |
| Ikotas Labs | Chained multiple issues, marked as a collision | $300,000 | 30 |
| Dimitrios Valsamaras, Ken Gannon, Tenia Valsamara | Remote 2-bug chain: 1 collision, 1 zero-day | $112,500 | 22.5 |
| White Noise Club (day one, October 6) | Failed: exploit did not work within the time limit | $0 | 0 |
Some early coverage rounded the Pixel 10 total to $560,000. Adding up ZDI's posted awards gives exactly $562,500. The $300,000 Pixel 10 win helped make Ikotas Labs the contest's overall Master of Pwn.
What does "collision" mean for Pixel 10 owners?
Pwn2Own pays full prizes only for bugs that the vendor and the organizers do not already know about. When an entry reuses a known bug, ZDI still counts the hack but usually pays less. For the Pixel 10, that means Google may already be aware of some of the flaws used on Thursday, but known is not the same as fixed: the phones were fully patched and were still broken into.
Only one of the three Pixel 10 chains contains a bug ZDI explicitly calls a zero-day. ZDI has not published how any of the three exploits work. The entries were registered as remote attacks, a category that covers web content in the default browser and radio links such as Wi-Fi, Bluetooth, NFC and the cellular baseband. Reports do not say which route each team used.
When will Google patch the Pixel 10?
Google has not given a date. Winning teams hand their exploits to ZDI, which passes the bugs to Google privately. Reports on this year's contest cite a 90-day window for Pwn2Own bugs before ZDI publishes the details, while ZDI's general disclosure policy gives vendors 120 days. Either way, the fix is most likely to arrive in a monthly Pixel security update over the next few months, not overnight.
The Google Pixel October 2026 update, released October 6 with patch level 2026-10-05, came out before the contest and does not mention it. Last month Google moved faster on an actively exploited flaw, the Pixel modem zero-day CVE-2026-58704, which was fixed in patch level 2026-09-05.
What should Google Pixel 10 owners do now?
There is nothing to install yet, and there is no report of these exploits being used against ordinary users. Pwn2Own bugs are reported privately so they can be fixed before the details go public. The useful step is to install each monthly update as soon as it lands:
- Open the Settings app.
- Tap System, then Software update.
- Check your update status and follow any on-screen steps.
Pixel phones were not the only Android target. ZDI's results show the Samsung Galaxy S26 was exploited in all seven attempts against it across the three days, and one bug in a day-one Galaxy S26 chain was "already known to the vendor (yet unpatched)". For a different kind of Android threat, where the danger is already on the phone when you buy it, see our report on Midnight Mimosa malware preinstalled on cheap Android phones.
Frequently Asked Questions
Was the Google Pixel 10 hacked at Pwn2Own 2026?
Yes. Three teams remotely exploited a fully patched Google Pixel 10 at Pwn2Own Ireland 2026 on October 8, earning $562,500 in total. One earlier attempt, on October 6, failed.
Is there a fix for the Pixel 10 Pwn2Own exploits?
Not yet. As of October 9, 2026, Google had not released a patch or made a statement about the Pwn2Own Ireland exploits. The bugs are passed to Google privately, and fixes usually arrive in a later monthly Pixel security update.
Is my Pixel 10 at risk from the Pwn2Own hacks?
The exploits worked on a fully patched Pixel 10, but their details are kept private while Google works on a fix, and there is no report of them being used against ordinary users. Installing every monthly Pixel update as soon as it arrives is the practical way to get the fix.
How much money did hackers win for the Pixel 10 at Pwn2Own Ireland 2026?
$562,500 across three teams: $300,000 for Ikotas Labs, $150,000 for Xint and $112,500 for the team of Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara. Some reports rounded the total to $560,000.
How do I check for a security update on a Google Pixel?
Open the Settings app, tap System, then Software update, and follow any on-screen steps. The Pixel October 2026 update, with patch level 2026-10-05, came out before Pwn2Own Ireland and does not include fixes for these exploits.
