Return to Threats

Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

thehackernews.com 2026-10-09 AI supply chain High

What Happened

Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero

Why It Matters

The report states that three teams remotely exploited fully patched Google Pixel 10 devices at Pwn2Own Ireland, using chains of vulnerabilities that could enable attacker-controlled code execution or sensitive-information access. The demonstrated issue concerns mobile-device software rather than an AI system, model, or AI-specific service. RealGround analysis: the article has limited direct relevance to the allowed AI risk categories, but it may inform broader software supply-chain and security-readiness reviews for AI-enabled mobile products or supporting infrastructure.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html

Talk to AI CISO