[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKVR3lYgDydAYrcFeBiDgGz6C19WAjStUzkNG66W_7tU":3},{"article":4,"iocs":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"b9c75b33-423e-4330-af39-257c9b575266","How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones","how-a-50-000-exploit-chain-turned-bixby-against-samsung-phones-e94e27","The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones appeared first on SecurityWeek.","Security researchers Dimitrios Valsamaras and Ken Gannon demonstrated a multi-stage exploit chain affecting Samsung Galaxy smartphones at Pwn2Own Ireland 2025, earning $50,000. The attack chains three vulnerabilities (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) across Samsung Members, Samsung Account, and Bixby to achieve system-level permissions and remote code execution. Samsung patched the vulnerabilities in November and December 2025, though older devices and those without all three apps installed may remain at risk.","Researchers exploit Samsung Members, Account, and Bixby vulnerabilities to achieve system-level compromise on Galaxy","BLACK HAT – Two security researchers found a way to exploit vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices. The research was conducted by Dimitrios Valsamaras, senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab. Gannon and Valsamaras demonstrated the vulnerabilities at the Pwn2Own Ireland hacking competition in October 2025, where they earned $50,000 after exploiting them to hack a Samsung Galaxy S25 device. The researchers have now detailed their findings in a talk at the Black Hat conference, describing the vulnerabilities they discovered and how they were chained to achieve remote system-level compromise. The exploit developed by Gannon and Valsamaras starts with an attacker tricking the targeted user into clicking a link delivered via malicious ads or a messaging application. After the victim clicks on the link, a vulnerability tracked as CVE-2025-21079 is exploited to force Samsung Members to connect to a malicious website. Samsung Members is an official user community, diagnostics, and support app that is preloaded on many mid-range and flagship Galaxy smartphones. Advertisement. Scroll to continue reading. The malicious site then forces Samsung Members to open the Samsung Account app, which is designed to connect users to Samsung services. Next, a different vulnerability, CVE-2025-58486, is used to force Samsung Account to connect to an attacker-controlled website. This site then exploits an XSS vulnerability tracked as CVE-2025-58487 to force Samsung Account to open Bixby, the virtual assistant that can handle voice commands, visual searches, and device automation routines. The researchers told SecurityWeek that this is possible because the Samsung Account app has a special permission that is required to interact with a specific ‘entry point’ in Bixby. “Think of it as a ‘side entrance’ and Samsung Account happens to be a key holder for the ‘side entrance,’” explained Gannon. The next stage of the attack involves a Capsule, a hidden background service inside an app that acts like a mini internal server. When users issue a voice command, Bixby translates the request and sends it to the app’s Capsule to perform the actual task. Because Capsules can directly control app functions, Samsung restricts access so that normally only Bixby is allowed to talk to them. However, the researchers reverse-engineered the Capsule infrastructure on Samsung phones and found a way to force Bixby to use various Capsules maliciously. This enabled an attacker to exfiltrate sensitive data and achieve system-level permissions on the Android device—the highest privilege level that can be achieved on a stock consumer device. The researchers showed that once an attacker has obtained ‘system’ permissions, they can achieve remote code execution and take control of the device. The researchers said they successfully reproduced the exploit on Samsung Galaxy S25, S24, and Flip 7 smartphones. Vulnerabilities patched by Samsung Samsung started patching the vulnerabilities a few weeks after the Pwn2Own competition. Specifically, the company rolled out patches for the Samsung Members application in November 2025, preventing the exploit chain from being triggered via a web browser or messaging app. Patches released in December fixed the Samsung Account flaws. The researchers told SecurityWeek that the attack works on older Samsung devices, which may not have received the patches, but noted that the exploit requires all of the targeted apps to be installed. While flagship models come with the apps preinstalled, it’s unclear if that applies to budget models as well. Samsung has not responded to SecurityWeek’s request for comment. Related: Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks Related: What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out Related: New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Water Sector Cyberattacks Reportedly Hit at Least 12 StatesTP-Link Omada ZTP Vulnerabilities Chain Into Full Network TakeoverMicrosoft Bug Bounty Program: $20 Million Paid to 500 ResearchersN‑able Patches Vulnerability Exploited to Hack N-central ServersUS Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other StatesPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 OrganizationsSemiconductor Firm Analog Devices Discloses Data Breach1 in 5 Data Center Assets Are Within Easy Reach of Attackers Latest News Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)The Fourth Battlefield: The Growing Role of Cyber Operations in Global ConflictNew Attack Methods Enable Malware to Hijack Passkey-Protected Accounts311,000 Impacted by Brown Health Medical Group-MA Data BreachCybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data AI Agents Targeted Real People and Projects During Cybersecurity TestsCISA Warns of Exploited Langflow, N-central, and Tomcat VulnerabilitiesOver 400 NPM Packages Infected in ChainDrop Supply Chain Attack Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.PNC Financial Services Group has appointed Christian Winward as CISO.More People On The MoveExpert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fhow-a-50000-exploit-chain-turned-bixby-against-samsung-phones\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F06\u002FSamsung-Android-Vulnerability.jpg","2026-08-05T19:40:00+00:00","2026-08-05T20:00:27.707598+00:00",9,[18,21,24,26,28,30],{"name":19,"type":20},"Samsung","vendor",{"name":22,"type":23},"Samsung Galaxy S25","product",{"name":25,"type":23},"Samsung Galaxy S24",{"name":27,"type":23},"Samsung Galaxy Flip 7",{"name":29,"type":23},"Bixby",{"name":31,"type":23},"Samsung Members","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,43],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",[49,53,56],{"type":50,"value":51,"context":52},"cve","CVE-2025-21079","Samsung Members vulnerability exploited to force connection to malicious website",{"type":50,"value":54,"context":55},"CVE-2025-58486","Samsung Account vulnerability used to force connection to attacker-controlled website",{"type":50,"value":57,"context":58},"CVE-2025-58487","XSS vulnerability in Samsung Account used to force opening of Bixby assistant"]