Security researchers have demonstrated a remote attack against Samsung’s Galaxy S26 that can reportedly compromise the phone simply by sending it a single email.

Japanese security company Ikotas Labs successfully exploited the Galaxy S26 at Pwn2Own Ireland 2026, a hacking competition organized by Trend Micro’s Zero Day Initiative (ZDI). The researchers used a chain of four vulnerabilities to execute their own code remotely on the smartphone, earning an $11,000 reward for the demonstration.

Ikotas said only one of the vulnerabilities in its attack chain was previously known to Samsung, while the remaining flaws were apparently new. Following the demonstration, the company said it had successfully achieved remote code execution on the Galaxy S26.

The researchers also claimed they had another, undisclosed attack chain capable of going further by achieving local privilege escalation after the initial compromise. Ikotas said it had discovered multiple remote code execution methods and planned to report the additional vulnerabilities to the affected vendors.

The Galaxy S26 was targeted several times during Pwn2Own Ireland. In total, researchers demonstrated three successful attacks against the device involving five apparently new vulnerabilities. Viettel Cyber Security’s Nguyen Thanh Dat used a four-bug chain containing three vulnerabilities already known to Samsung, while researchers from Interrupt Labs demonstrated another four-bug chain involving three previously discovered vulnerabilities and one zero-day.

Ikotas has also claimed that the zero-day used in its research affects Google’s Pixel 10 alongside the Galaxy S26. Ikotas CEO Satoki Tsuji said the vulnerability could allow remote code execution on the latest Pixel 10 and Galaxy S26 versions after sending a single email, although the company has not publicly disclosed the technical details needed to reproduce the attack.

READ
WordPress 7.1.3 Released With 7 Security Fixes

The researchers are scheduled to attempt a remote compromise of the Pixel 10 during Pwn2Own Ireland on October 8. The demonstration could provide more information about whether the same underlying vulnerability affects Google’s device and how the attack works.

Ikotas has also highlighted a potential law enforcement application for the technology. The company said remote smartphone exploitation could potentially be used for criminal investigations where authorities need to access locked devices. The comments come amid growing interest in remote smartphone analysis and government hacking capabilities.

However, the technical details of the newly demonstrated vulnerabilities have not yet been publicly released. ZDI has not published CVE numbers, affected components or severity ratings for the new flaws, so the exact impact and attack requirements remain unclear.

More Galaxy S26 hacking attempts were scheduled as Pwn2Own Ireland continued, meaning additional vulnerabilities and attack techniques could be disclosed during the event.


Buy ExpressVPN with PayPal or Credit Card

Advertisement