Samsung Galaxy S26 Hacked Again as Pwn2Own Researchers Find More Flaws

Samsung's Galaxy S26 was hacked repeatedly at Pwn2Own Ireland. Learn what researchers found, why exploit chains matter and what users should know.

Oct 9, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Samsung's Galaxy S26 faced three more successful hacking attempts on the second day of Pwn2Own Ireland, following several exploits demonstrated during the competition's opening day.

Researchers from KAIST Hacking Lab, PetoWorks and CENSUS Labs successfully targeted the flagship smartphone, according to BleepingComputer.

The repeated compromises highlight the value of coordinated vulnerability research, particularly when attackers can combine weaknesses to bypass device protections. However, the competition results do not establish that the demonstrated exploits are being used against Samsung customers in the wild.

Zero days and bug bounties: how the discoveries unfolded

The Galaxy S26 compromises involved vulnerabilities that were both newly discovered and already known to Samsung. On the first day, Viettel Cyber Security, Interrupt Labs and Ikotas Labs successfully exploited the phone, with some of the bugs already known to the vendor.

The second day brought the headline-grabbing vulnerabilities: three more successful attacks from unknown flaws. According to BleepingComputer, the Samsung exploit winners comprised a team from Dimitrios Valsamaras, Ken Gannon, and CENSUS Labs's Tenia Valsamara. Others include KAIST Hacking Lab's Kyeongmin Kim and PetoWorks. 

A total of $232,500 was awarded for 45 unique zero-day flaws on day two, while the findings will now move into disclosure and remediation. 

The event also saw participation from other vendors across smartphones, printers, AI infrastructure and coding apps, messaging apps, and smart home devices. BleepingComputer says wellness healthcare devices are a new addition, which matters because the healthcare industry has seen a rapid influx of technology that has also attracted serious cyberattacks.

Beyond Samsung, the Apple iPhone 17 is also listed with a $300,000 total bounty, but no one has registered to try to exploit it. 

Advertisement

The hidden risks of bug chaining

The Galaxy S26 demonstrations show why you can't always judge a vulnerability's impact in isolation. Some successful attacks at Pwn2Own chained multiple bugs, showing how weaknesses can combine to compromise a device rather than rely on one critical flaw.

For example, a minor flaw might let an attacker bypass one security restriction, while another could let them execute code or gain additional access. Chained together, weaknesses that appear limited individually could create a route to a much more serious compromise. 

The published reporting does not establish that every Galaxy S26 team used this exact sequence, but the principle is central to understanding multi-bug exploits.

This creates a problem: patching one vulnerability may close one route while leaving other weaknesses available to form another chain. 

Samsung, and more broadly, defenders, must therefore assess how flaws work together, not simply fix each bug in isolation, to ensure attack paths are properly closed.

Security takeaway for users

Time does not automatically make a device more secure. The Galaxy S26 has been on the market for months, yet researchers continued to demonstrate successful exploits at Pwn2Own Ireland.

That creates a wider problem for both consumers and businesses. A device may have received updates and still contain undiscovered weaknesses, while known bugs can remain exploitable until patches are developed and installed. 

What matters is whether vulnerabilities are found, how they can be exploited, and whether the fixes close the available attack paths.

For users, installing security updates remains one of the most effective ways to reduce exposure once fixes become available. Businesses managing Samsung devices should also monitor vendor advisories, track affected software versions and deploy patches promptly.

The broader lesson is that smartphone security depends on continuous testing and remediation. Finding vulnerabilities is only part of the process; what matters next is how quickly manufacturers can investigate the flaws, develop fixes and deliver them to users.

Advertisement

Other news: IBM and Red Hat have addressed more than 400 security vulnerabilities in widely used Java libraries through an initiative combining AI-assisted patching with automated testing and human review.


Joseph Chisom Ofonagoro

Joseph is a Technical Writer with about 3 years of experience in the industry, also advancing a career in cyber threat intelligence. He is passionate about the responsible use of technology, a passion that led him into cybersecurity. As an undergrad, he leads a novel community of technology enthusiasts at his school, NOUN, where he guides and shares resources for beginners in tech. His writing experience includes a diverse range of topics, from consumer tech to startups to tutorials. Additionally, he periodically shares case studies and research reports on cybersecurity on his social media pages.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.