Particle.news
Download on the App Store

Pwn2Own Ireland Awards $1.02 Million for 73 Zero‑Days as Summoning Team Wins Master of Pwn

Vendors now enter a 90‑day window to patch the flaws under ZDI disclosure rules.

Overview

  • The three‑day contest in Cork ran October 21–23 and targeted eight categories spanning flagship phones, NAS, printers, home networking, messaging apps, smart‑home and surveillance gear, and wearables.
  • Summoning Team topped the leaderboard with 22 Master of Pwn points and $187,500, followed by Team ANHTUD in second and Team Synactiv in third.
  • Reports on the Samsung Galaxy S25 hack diverge, with a ZDI post crediting Ken Gannon of Mobile Hacking Lab and Dimitrios Valsamaras of Summoning Team for a five‑bug chain, while final‑day coverage credits Interrupt Labs for an improper input validation exploit worth $50,000 and 5 points.
  • This edition added a locked‑device USB attack vector for mobile handsets, alongside established wireless paths such as Bluetooth, Wi‑Fi and NFC.
  • Team Z3 withdrew a planned zero‑click WhatsApp demonstration and opted for private disclosure to ZDI before engagement with Meta’s engineering team.