THREE teams demonstrated remote exploits against Google’s Pixel 10 at Pwn2Own Ireland on 8 October 2026, with the event confirming patches were required for targets. The Pixel 10 entries were remote exploits, meaning breaches were delivered via web content in the default browser or through one of four radios: NFC, Wi‑Fi, Bluetooth or baseband.
The results, published by Trend Micro’s ZDI, show three Pixel 10 wins, a total payout of $562,500, and the winners all classified their entries as “collisions” or as a chain including a zero‑day, though the exact technical details of the exploits were not disclosed in the post on 9 October 2026. The rule set requires bugs not yet known to the vendor, with collisions optionally allowed at a lower prize.
The prize breakdown was as follows: Xint (Tim Becker and Yves Bieri) earned $150,000 for a single bug collision; Ikotas Labs received the top prize of $300,000 for “chaining multiple issues together” (also labelled a collision); and Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara earned $112,500 for a two‑bug chain consisting of one collision and one zero‑day. All three Pixel 10 entries were registered as remote exploits, and the teams handed their exploits and write‑ups to ZDI for responsible disclosure.
Separately, Google had previously patched a Pixel modem flaw, CVE-2026-58704, with devices on patch level 2026‑09‑05 or later considered protected.