Security researchers successfully attacked a Google Pixel 10, a Brother MFC-L8970CDW printer and several smart-home and enterprise products on day three of Pwn2Own Ireland 2026. Owners do not need to panic, but should watch for vendor updates once the reported flaws are investigated and patches become available.
The published results do not provide enough detail to determine the exact exposure for Pixel owners. Until Google issues product-specific guidance, users should install Android and Google Play system updates promptly rather than changing settings based only on the contest result.
Team DDOS used a five-bug chain against Home Assistant Green, including one zero-day. Summoning Team also succeeded against the Philips Hue Bridge Pro, although all five bugs in that chain were collisions.
OtterSec researchers compromised Oracle Autonomous AI Database with four linked bugs: three collisions and one zero-day. The result earned $6,250 and 2.5 points.
Pixel 10 exploit delivers the day’s largest confirmed award
Trend Micro’s Zero Day Initiative, writing at www.thezdi.com, reported that Tim Becker and Yves Bieri of Xint remotely exploited the Google Pixel 10. The attack used one previously known bug—a “collision” in contest terminology—and earned the team $150,000 plus 15 Master of Pwn points.The published results do not provide enough detail to determine the exact exposure for Pixel owners. Until Google issues product-specific guidance, users should install Android and Google Play system updates promptly rather than changing settings based only on the contest result.
Printer, smart-home and database targets also breached
FuzzingLabs researchers Lucas Van Haaren and Hugo Leclercq exploited the Brother MFC-L8970CDW using a single zero-day, meaning a vulnerability that did not yet have a vendor fix at the time of the contest. They received $20,000 and two points.Team DDOS used a five-bug chain against Home Assistant Green, including one zero-day. Summoning Team also succeeded against the Philips Hue Bridge Pro, although all five bugs in that chain were collisions.
OtterSec researchers compromised Oracle Autonomous AI Database with four linked bugs: three collisions and one zero-day. The result earned $6,250 and 2.5 points.
- Pixel 10 users: install Google’s security updates when offered and monitor official Pixel security notices.
- Brother MFC-L8970CDW owners: check Brother’s support page for firmware updates and avoid exposing the printer directly to the internet.
- Home Assistant Green and Philips Hue Bridge Pro users: keep device software current and watch the vendors’ release notes for fixes tied to the contest findings.