← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Researchers Exploit Samsung Bixby and Software Vulnerabilities to Hack Galaxy Phones

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Exploit chain used vulnerabilities in Samsung Members, Samsung Account, and Bixby.
  • Achieved remote system-level compromise on a Samsung Galaxy S25.
  • Researchers earned $50,000 at Pwn2Own Ireland for the exploit.
  • Attack starts with a malicious link click by the user.

Vulnerability Discovery and Demonstration

Dimitrios Valsamaras, a senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab, discovered and demonstrated an exploit chain targeting Samsung mobile devices. They presented their findings at the Black Hat conference, detailing the vulnerabilities and their method of exploitation.

Pwn2Own Success

In October 2025, Gannon and Valsamaras successfully exploited these vulnerabilities at the Pwn2Own Ireland hacking competition. They used their exploit chain to compromise a Samsung Galaxy S25 device, earning a $50,000 reward for their efforts.

Exploit Chain Mechanism

The attack begins when a user clicks a malicious link, delivered via ads or messaging. This link exploits CVE-2025-21079 to force the Samsung Members app, preloaded on many Galaxy phones, to connect to a malicious website. This site then forces Samsung Members to open the Samsung Account app.

A second vulnerability, CVE-2025-58486, is used to make Samsung Account connect to an attacker-controlled website. This site then exploits an XSS vulnerability (CVE-2025-58487) to force Samsung Account to open Bixby. The researchers noted that Samsung Account has a specific permission allowing it to interact with a particular 'entry point' in Bixby.

Bixby Capsule Exploitation

The final stage of the attack involves Bixby's 'Capsules,' which are hidden background services within apps that act as internal servers. Normally, only Bixby can communicate with these Capsules to execute tasks based on voice commands. However, the researchers reverse-engineered the Capsule infrastructure and found a way to force Bixby to use various Capsules, indicating a potential bypass of intended security restrictions.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Security researchers demonstrated an exploit chain leveraging vulnerabilities in Samsung Members, Samsung Account, and Bixby to achieve remote system-level compromise on Samsung Galaxy S25 devices. This exploit chain, which earned $50,000 at Pwn2Own, highlights potential security weaknesses in preloaded Samsung applications and the Bixby virtual assistant.