A group of cybersecurity experts has managed to hack a Galaxy S26, Samsung’s flagship smartphone, simply by sending an email. The feat was presented during the Pwn2Own Ireland 2026 cybersecurity event, where researchers demonstrated how to take remote control of the phone without the user having to interact or open any suspicious links.
The attack was executed by the Japanese company Ikotas Labs, whose specialists combined four security flaws in the system to access the device.
Although the Korean manufacturer was already aware of one of these errors, the other three were completely unknown until now, which in the tech sector is referred to as zero-day vulnerabilities. For this discovery, the team of analysts received a prize of $11,000.
“We have successfully executed remote code on the Samsung Galaxy S26. Although we received a substantial reward, the joy of demonstrating our technical prowess on the international stage is even greater,” stated Ikotas.
The vulnerability could be even more severe than anticipated, as the researchers themselves warn that this same flaw could also affect the Google Pixel 10 and possibly the Google Pixel 11.
According to the experts, the breach allows not only remote control of the smartphone via email but also privilege escalation within the device to access much deeper and protected functions and data.
It was not the only security hole in the S26
“I have discovered multiple remote code execution methods for each device and plan to notify the manufacturers,” announced Satoki Tsuji, CEO of Ikotas Labs, in a post on X prior to the event.
During the competition, two other successful attacks against the same Samsung model were also demonstrated, bringing the total to five new flaws discovered in the device.
The security firms involved have noted that these types of techniques also attract interest in the police and judicial fields, where there is a growing demand for tools that allow authorities to access mobile phones during criminal investigations.
For now, the specific technical details and exact severity of the flaws have not been published to prevent malicious individuals from exploiting them.
Samsung and Google are already working on developing security patches to address these issues in future software updates before the vulnerabilities are disclosed to the general public.
Click Here For The Original Source.
