Dimitrios Valsamaras, a senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab, discovered and demonstrated an exploit chain targeting Samsung mobile devices. They presented their findings at the Black Hat conference, detailing the vulnerabilities and their method of exploitation.
In October 2025, Gannon and Valsamaras successfully exploited these vulnerabilities at the Pwn2Own Ireland hacking competition. They used their exploit chain to compromise a Samsung Galaxy S25 device, earning a $50,000 reward for their efforts.
The attack begins when a user clicks a malicious link, delivered via ads or messaging. This link exploits CVE-2025-21079 to force the Samsung Members app, preloaded on many Galaxy phones, to connect to a malicious website. This site then forces Samsung Members to open the Samsung Account app.
A second vulnerability, CVE-2025-58486, is used to make Samsung Account connect to an attacker-controlled website. This site then exploits an XSS vulnerability (CVE-2025-58487) to force Samsung Account to open Bixby. The researchers noted that Samsung Account has a specific permission allowing it to interact with a particular 'entry point' in Bixby.
The final stage of the attack involves Bixby's 'Capsules,' which are hidden background services within apps that act as internal servers. Normally, only Bixby can communicate with these Capsules to execute tasks based on voice commands. However, the researchers reverse-engineered the Capsule infrastructure and found a way to force Bixby to use various Capsules, indicating a potential bypass of intended security restrictions.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security researchers demonstrated an exploit chain leveraging vulnerabilities in Samsung Members, Samsung Account, and Bixby to achieve remote system-level compromise on Samsung Galaxy S25 devices. This exploit chain, which earned $50,000 at Pwn2Own, highlights potential security weaknesses in preloaded Samsung applications and the Bixby virtual assistant.