Samsung's Galaxy S26 faced three more successful hacking attempts on the second day of Pwn2Own Ireland, following several exploits demonstrated during the competition's opening day.
Researchers from KAIST Hacking Lab, PetoWorks and CENSUS Labs successfully targeted the flagship smartphone, according to BleepingComputer.
The repeated compromises highlight the value of coordinated vulnerability research, particularly when attackers can combine weaknesses to bypass device protections. However, the competition results do not establish that the demonstrated exploits are being used against Samsung customers in the wild.
Zero days and bug bounties: how the discoveries unfolded
The Galaxy S26 compromises involved vulnerabilities that were both newly discovered and already known to Samsung. On the first day, Viettel Cyber Security, Interrupt Labs and Ikotas Labs successfully exploited the phone, with some of the bugs already known to the vendor.
The second day brought the headline-grabbing vulnerabilities: three more successful attacks from unknown flaws. According to BleepingComputer, the Samsung exploit winners comprised a team from Dimitrios Valsamaras, Ken Gannon, and CENSUS Labs's Tenia Valsamara. Others include KAIST Hacking Lab's Kyeongmin Kim and PetoWorks.
A total of $232,500 was awarded for 45 unique zero-day flaws on day two, while the findings will now move into disclosure and remediation.
The event also saw participation from other vendors across smartphones, printers, AI infrastructure and coding apps, messaging apps, and smart home devices. BleepingComputer says wellness healthcare devices are a new addition, which matters because the healthcare industry has seen a rapid influx of technology that has also attracted serious cyberattacks.
Beyond Samsung, the Apple iPhone 17 is also listed with a $300,000 total bounty, but no one has registered to try to exploit it.
The hidden risks of bug chaining
The Galaxy S26 demonstrations show why you can't always judge a vulnerability's impact in isolation. Some successful attacks at Pwn2Own chained multiple bugs, showing how weaknesses can combine to compromise a device rather than rely on one critical flaw.
For example, a minor flaw might let an attacker bypass one security restriction, while another could let them execute code or gain additional access. Chained together, weaknesses that appear limited individually could create a route to a much more serious compromise.
The published reporting does not establish that every Galaxy S26 team used this exact sequence, but the principle is central to understanding multi-bug exploits.
This creates a problem: patching one vulnerability may close one route while leaving other weaknesses available to form another chain.
Samsung, and more broadly, defenders, must therefore assess how flaws work together, not simply fix each bug in isolation, to ensure attack paths are properly closed.
Security takeaway for users
Time does not automatically make a device more secure. The Galaxy S26 has been on the market for months, yet researchers continued to demonstrate successful exploits at Pwn2Own Ireland.
That creates a wider problem for both consumers and businesses. A device may have received updates and still contain undiscovered weaknesses, while known bugs can remain exploitable until patches are developed and installed.
What matters is whether vulnerabilities are found, how they can be exploited, and whether the fixes close the available attack paths.
For users, installing security updates remains one of the most effective ways to reduce exposure once fixes become available. Businesses managing Samsung devices should also monitor vendor advisories, track affected software versions and deploy patches promptly.
The broader lesson is that smartphone security depends on continuous testing and remediation. Finding vulnerabilities is only part of the process; what matters next is how quickly manufacturers can investigate the flaws, develop fixes and deliver them to users.
Other news: IBM and Red Hat have addressed more than 400 security vulnerabilities in widely used Java libraries through an initiative combining AI-assisted patching with automated testing and human review.





