← Back to Daily Briefing (#Pwn2Own)

Samsung Galaxy S26 Exploited: 32 Zero-Days Demonstrated on Day One of Pwn2Own Ireland 2026

Published October 7, 2026

On October 6, 2026, the opening day of Pwn2Own Ireland 2026 in Cork, security researchers demonstrated 32 previously unknown zero‑day vulnerabilities across multiple platforms, with the Samsung Galaxy S26 (Android 15) serving as a primary high‑value target. Three distinct exploit chains compromised the device, combining kernel use‑after‑free, binder IPC race conditions, and sandbox escapes via WebView to achieve full privileged code execution. The chains earned $342,500 in awards for 28 zero‑days (some incorporating known CVEs). The findings underscore the depth of mobile attack surfaces and the effectiveness of multi‑stage exploits that blend memory‑corruption, logic flaws, and privilege‑escalation primitives, placing millions of Galaxy S26 devices at risk until vendor patches are deployed.

  • Overview & Scope
  • 32 zero‑days demonstrated on day one; 28 rewarded, total prize $342,500.
  • Primary focus: Samsung Galaxy S26 (Android 15) compromised three times via distinct chains.
  • Additional demonstrations included iOS 18 privilege escalation, IoT smart‑hub RCE, and a VPN client token‑reuse logic flaw.

  • Exploit Mechanics & Technical Details

  • Galaxy S26 Chain A: kernel use‑after‑free in binder driver → arbitrary kernel write → privilege escalation.
  • Chain B: binder IPC race condition leading to use‑after‑free in a system service, combined with WebView sandbox escape via JSBridge misuse.
  • Chain C: WebView‑based ROP chain exploiting a JavaScript engine flaw to break out of the isolated process and gain root.
  • iOS 18: mach‑port replacement and task‑for‑pid bypass enabling kernel‑level code execution.
  • IoT hub: stack buffer overflow in HTTP parser → ROP → remote command execution.
  • VPN client: token‑reuse logic flaw allowing session hijacking without authentication.

  • Impact & Risk Assessment

  • Estimated millions of Galaxy S26 devices exposed until Samsung releases security patches.
  • Vulnerabilities rated CVSS ≥9.0 for kernel and sandbox escapes; critical severity.
  • Demonstrated exploit chains illustrate hybrid use of known CVEs to reduce bounty, showing real‑world attackers may chain old and new flaws.
  • Cross‑platform relevance: similar binder and WebView attack surfaces exist on other Android OEMs; iOS mach‑port flaws affect all iOS 18 devices; IoT hub flaw affects a widely deployed smart‑home product line.

  • Detection, Mitigation & Remediation

  • Apply Samsung’s forthcoming security update for Android 15 (patch level 2026‑10‑01 or later) to close kernel use‑after‑free and binder race flaws.
  • Enable SELinux enforcing mode and restrict WebView to trusted content; consider disabling JavaScript in WebView where not required.
  • Monitor for abnormal binder IPC traffic and unexpected WebView process spawning via EDR solutions.
  • For iOS, enforce latest iOS 18.x updates that address mach‑port replacement mitigations.
  • IoT devices: upgrade firmware to vendor‑provided version that includes stack‑overflow mitigations (e.g., stack canaries, ASLR).
  • VPN clients: enforce token rotation and short‑lived sessions; validate token bindings server‑side.

  • Conclusion & Strategic Takeaways

  • The event confirms that mobile and embedded platforms remain high‑value targets for sophisticated, multi‑stage zero‑day exploits.
  • Defenders must prioritize patch management for kernel and sandbox components, and adopt defense‑in‑depth that limits IPC attack surface.
  • Exploit developers increasingly blend known and unknown vulnerabilities; vulnerability management should treat known CVEs as potential stepping stones.
  • Continuous red‑team testing against WebView, binder, and mach‑port interfaces is advisable to catch similar chains early.

Related posts

  1. cyberinsider.com — Samsung Galaxy S26 hacked three times at Pwn2Own Ireland 2026
  2. Mallory
  3. Trendmicro
  4. Infosecurity-magazine
  5. Facebook
  6. Firsthackersnews
  7. Rapid7
  8. Cloaked

LINK COPIED TO CLIPBOARD