Researchers from the Japanese company Ikotas Labs demonstrated a remote hack of the Samsung Galaxy S26 during the Pwn2Own Ireland 2026 competition. According to the researchers, a single email is enough to carry out the attack, and the vulnerabilities used could also pose a threat to Google Pixel 10 smartphones.
Japanese company Ikotas Labs successfully executed its own code on the Samsung Galaxy S26 during the Pwn2Own Ireland 2026 competition, held from October 6 to 9 in Cork, Ireland. The attack was demonstrated on October 6 using a chain of four vulnerabilities, three of which were previously unknown to the manufacturer.
What makes this attack particularly notable is that it does not require physical access to the smartphone. According to the researchers, a single email is enough to execute malicious code. However, the exact exploitation mechanism has not yet been disclosed, making it impossible to independently verify all the details of the attack.
The team received an $11,000 reward for the successful demonstration. As confirmed by the Zero Day Initiative, one of the vulnerabilities used in the attack was already known to Samsung but remained unpatched at the time of the competition.
“We successfully achieved remote code execution on the Samsung Galaxy S26,” Ikotas Labs researchers announced on X.
The team also noted that the opportunity to demonstrate its technical expertise on the international stage was even more rewarding than the prize money.
On October 1, Ikotas Labs CEO Satoki Tsuji announced on X that the discovered zero-day vulnerability could affect not only the Samsung Galaxy S26 but also the latest versions of the Google Pixel 10. He suggested that the issue might even extend to the upcoming Pixel 11, although this has not yet been confirmed.
The vulnerability involves RCE (Remote Code Execution), which allows code to be executed remotely on a device. According to Tsuji, exploiting it requires nothing more than sending a single email to the smartphone.
The researcher also revealed another vulnerability chain that could allow attackers to escalate their privileges after the initial compromise. This type of attack is known as LPE (Local Privilege Escalation) and could potentially give attackers greater control over the device.
Tsuji also claims to have discovered multiple methods of achieving remote code execution on each smartphone. He plans to report all identified vulnerabilities to the respective manufacturers so they can develop and release security patches.
According to the official Pwn2Own Ireland 2026 schedule, Ikotas Labs also planned to attempt a remote hack of the Google Pixel 10 on October 8. A successful attack in this category could earn a reward of up to $300,000.
Ikotas Labs was not the only team to bypass Samsung’s flagship smartphone security. On October 6 alone, researchers demonstrated three successful attacks against the Galaxy S26 during Pwn2Own Ireland 2026, exploiting five vulnerabilities believed to have been previously unknown.
Nguyen Thanh Dat from Viettel Cyber Security used a chain of four security vulnerabilities, three of which were already known to Samsung. His successful demonstration earned him $31,250.
The Interrupt Labs team also successfully compromised the smartphone using four vulnerabilities. Three overlapped with flaws previously discovered by other researchers, while the fourth was a new zero-day vulnerability. The team received $15,750 for its demonstration.
These results show that several independent teams discovered different ways to bypass the security protections of one of Samsung’s latest flagship smartphones. In some cases, the successful attacks exploited vulnerabilities that the manufacturer was already aware of but had not yet patched.
According to the results of the competition’s second day, three more teams successfully attacked the Galaxy S26 on October 7. Researchers demonstrated both the exploitation of individual vulnerabilities and attack chains combining multiple security flaws. In total, six successful hacking demonstrations targeting the smartphone took place during the first two days of the competition.
Ikotas Labs sees its technology not only as a way to identify weaknesses in smartphones but also as a potential tool for digital forensics and law enforcement agencies.
In an October 1 statement, the company explained that demand for remote smartphone examination technologies in criminal investigations is growing. Its demonstration at Pwn2Own is intended to show that Japanese specialists are capable of independently developing such tools.
“Amid growing demand for the introduction of remote smartphone analysis methods in criminal investigations, we will demonstrate that a domestic company has the technical capability to implement such technologies.”
Similar technologies are already being used by law enforcement agencies in various countries. For example, in 2024, the FBI used software developed by Israeli company Cellebrite to gain access to the smartphone of the man who attempted to assassinate Donald Trump. After obtaining an updated version of the tool, investigators needed approximately 40 minutes to unlock the device.
Ikotas Labs’ developments are also attracting attention amid changes in Japan’s cybersecurity policy. The country is expanding the powers of government agencies to actively counter cyberattacks, including the ability to disable servers and devices used in hostile operations.
The organizers of Pwn2Own Ireland 2026, Trend Micro’s Zero Day Initiative, have not yet published CVE identifiers, information about the affected components, or technical details of the newly discovered vulnerabilities. As a result, it remains unclear which smartphone security mechanisms were bypassed and how severe the identified flaws actually are.
There is also no confirmation that these exploits have been used in real-world attacks against Samsung Galaxy S26 or Google Pixel 10 owners. The demonstrated hacks took place under controlled conditions during the cybersecurity competition.
Manufacturers still need to thoroughly investigate the identified security flaws. Until technical documentation and the corresponding security patches become available, the full scope of the problem remains unknown.
The Pwn2Own results once again demonstrate that even the latest flagship smartphones can contain serious security vulnerabilities. Attacks that do not require physical access to a device are particularly concerning, as they could potentially allow attackers to compromise users’ smartphones remotely.