Vulnerabilities · 9h ago
Zero Day Initiative said day one of Pwn2Own Ireland 2026 produced 32 zero-day disclosures and more than $368,000 in prize money, with targets spanning smartphones, smart home gear, printers, and AI tools such as OpenAI Codex and LiteLLM. The first-day list also included successful hits on Sonos Era 300, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, and Garmin Index BPM.
The AI-tool wins were straightforward trust-boundary failures: Ikotas Labs said a single argument injection bug was enough to exploit OpenAI Codex, and Xint used improper input validation plus code injection to get a reverse shell on LiteLLM. That matters because once a tool treats attacker-controlled input as something it can act on, it can move from answering prompts to running code.
The broader signal is where contest attention is landing. If your environment uses assistants or automation that accept untrusted prompts or arguments and can take actions, these results show that AI tooling and consumer devices are already yielding high-impact bugs quickly, not just isolated crashes.
3 sources covering this story
Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One
Ethical hackers have already found 32 zero days in various products at Pwn2Own Ireland
Zero Day Initiative — Pwn2Own Ireland 2026 - Day Two Results
Day Two of Pwn2Own Ireland 2026 has 24 attempts on the docket, with roughly $780,000 up for grabs, running 9:30 AM to 7:30 PM IST.
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days.
Zero Day Initiative — Pwn2Own Ireland 2026 - Day One Results
Welcome to Day One of Pwn2Own Ireland 2026!
Part of the PlainSec briefing for 2026-10-07