[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhaM55kN3EriITd6Z_xvk3KoaPQMPgxWVBpf9kuZBCIY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"0c01ce0f-ca93-40b7-8557-7765a6127052","fully-patched-pixel-10-hacked-remotely-at-pwn2own-via-chained-exploits","9651ce0e-8da6-48e4-94b2-7ffe74a5a2a4","Fully Patched Pixel 10 Hacked Remotely at Pwn2Own via Chained Exploits","Three research teams successfully compromised fully patched Google Pixel 10 devices at Pwn2Own Ireland, with at least two exploits leveraging previously known but unpatched or insufficiently mitigated vulnerabilities — a phenomenon called 'collisions.' This demonstrates that being 'fully patched' does not equate to being fully secure, as vendor patch cycles can lag behind known vulnerability disclosure. Chaining multiple lower-severity bugs into a single high-impact exploit is a common real-world attacker technique that bypasses traditional patch-centric defenses. Organizations relying solely on patch status as their security benchmark are exposed to residual risk from known vulnerabilities that lack available fixes or whose patches are delayed.","**Immediate actions:**\n- Audit mobile device fleets for known vulnerabilities using a CVE tracking tool, even when devices report as 'fully patched.'\n- Apply compensating controls (e.g., MDM restrictions, network isolation) for high-value devices pending vendor patches.\n- Subscribe to vendor security advisories (e.g., Google Android Security Bulletins) to receive timely notification of emerging threats.\n\n**Long-term improvements:**\n- Implement a formal vulnerability management program that tracks known-but-unpatched CVEs across all device types including mobile endpoints.\n- Enforce a zero-trust mobile access model so that a compromised device cannot pivot to sensitive corporate resources.\n- Work with vendors to evaluate their patch SLA commitments and escalate unresolved known vulnerabilities through responsible disclosure channels.\n\n**Detection measures:**\n- Deploy Mobile Threat Defense (MTD) solutions capable of detecting exploit behavior at runtime, independent of patch status.\n- Enable centralized logging of mobile device telemetry and integrate with a SIEM to detect anomalous activity indicative of exploitation.\n- Conduct regular red team exercises or participate in bug bounty programs to discover exploit chains before adversaries do.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 4: Secure Configuration of Enterprise Assets","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-124: Guidelines for Managing the Security of Mobile Devices","NIST Cybersecurity Framework ID.RA-1: Asset vulnerabilities are identified and documented","ISO\u002FIEC 27001 A.12.6.1: Management of Technical Vulnerabilities","OWASP Mobile Security Testing Guide (MSTG)","ITIL Change Management: Emergency Change procedures for critical patches","published","2026-10-09T10:21:50.673087+00:00","2026-10-09T10:21:50.354+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fthree-teams-demonstrate-remote-hacks-of.html","three-teams-demonstrate-remote-hacks-of-fully-patched-google-pixel-10-at-pwn2own-b0109e","Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]