Back to advisories

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain exploitable. This is a weaponized, publicly demonstrated attack.

CRITICALAdvisoryAug 06, 2026
Action required
Verify all Samsung Galaxy devices in your environment are patched for all three CVEs (November/December 2025 updates minimum). Audit which devices lack Samsung Members, Account, or Bixby apps installed, as partial deployments may block exploitation but still need firmware validation.
Affected products
SamsungSamsung Galaxy S25Samsung Galaxy S24Samsung Galaxy Flip 7Bixby