Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Summary

Three research teams successfully demonstrated remote exploits against fully patched Google Pixel 10 devices at the Pwn2Own Ireland hacking contest. One of these exploits, by Ikotas Labs, earned them $300,000 and the contest's overall win.

IFF Assessment

FOE

The demonstration of successful remote exploits against a fully patched device indicates potential unknown vulnerabilities or advanced attack techniques that defenders need to be aware of.

Severity

8.1 High (AI Estimated)

The exploit allows for remote code execution on a fully patched device, impacting confidentiality, integrity, and availability. The specific CVSS score is estimated based on the severity of a remote, unauthenticated exploit capable of taking over a device, assuming a common attack vector and user interaction might be required (though not explicitly stated as a limitation).

Defender Context

This event highlights the ongoing cat-and-mouse game between vulnerability researchers and device manufacturers. Defenders must assume that even 'fully patched' devices can have unknown vulnerabilities, necessitating robust layered security and proactive threat hunting.

Read Full Story →