The Samsung Galaxy S26 faced a difficult second day at Pwn2Own Ireland, with security researchers successfully compromising the device three more times. This brings the total number of unique breaches against Samsung’s flagship phone to six within the first 48 hours of the competition.
During the second day of the event, various research teams earned a combined $232,500 in cash awards while identifying 45 unique zero-day vulnerabilities across multiple targets. The Galaxy S26 remained a primary focus, consistently falling to different exploit chains despite the security patches currently available to the public.
One of the most notable exploits on the second day was characterized as a “1-bug wonder.” The Mobile Hacking Lab team utilized a Confused Deputy vulnerability, specifically classified as CWE-441, to achieve their breach. This type of flaw occurs when a privileged entity is tricked into performing an action on behalf of a less privileged one, effectively bypassing security boundaries.

The mounting pressure on the S26 follows a similarly volatile opening day. During the first 24 hours of Pwn2Own Ireland, the device was hacked three times by teams representing Viettel Cyber Security, Interrupt Labs, and Ikotas Labs. While the Galaxy S26 has been repeatedly compromised, other mobile targets have shown varying levels of resilience; for instance, the Google Pixel 10 resisted early attempts to breach its security on the first day.
The high volume of successful exploits against the S26 highlights the intensity of the current threat landscape, which now includes expanded targets such as AI infrastructure. This year’s competition has introduced categories for OpenAI Codex and the Oracle Autonomous AI Database, reflecting the shifting priorities of both attackers and defenders in the security industry.
Technical Vulnerabilities and Researcher Success
The Pwn2Own competition serves as a high-stakes environment for vendors to stress-test their hardware against the world’s most capable independent researchers. By the end of the second day, the sheer number of zero-day vulnerabilities discovered—45 in total—suggests that even modern, high-end mobile devices harbor complex security gaps that can be chained together for unauthorized access.
The specific details regarding how these exploits were executed remain confidential for now. Following the standard operating procedures of the Zero Day Initiative, all vulnerability data is shared directly with the affected vendors. Samsung and other targeted companies now have a 90-day disclosure window to develop and distribute security patches to the public. Only after this period, or once a patch is released, are the full technical specifics of the vulnerabilities typically made public.
For Galaxy S26 users, these results do not necessarily imply an immediate risk of widespread exploitation, as the vulnerabilities were demonstrated under controlled competition conditions by elite researchers. However, the results emphasize the necessity of installing security updates as soon as they become available over the next three months. Researchers continue to probe the remaining targets as the competition enters its final stages, with the total payout and vulnerability count expected to rise further.
