Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Researchers Uncover K Exploit Chain in Samsung Phones

Researchers Uncover $50K Exploit Chain in Samsung Phones

Posted on August 5, 2026 By CWS

At the forefront of mobile security discussions, two researchers have uncovered a significant vulnerability chain in Samsung’s software, including the virtual assistant Bixby. Their findings, which earned them $50,000, were demonstrated at the Pwn2Own Ireland hacking competition in October 2025.

Security Experts Reveal Exploit Details

Microsoft’s Dimitrios Valsamaras and Ken Gannon from Mobile Hacking Lab spearheaded the research. They showcased their discoveries at the Black Hat conference, detailing the method of linking various vulnerabilities to achieve a remote system-level breach of Samsung Galaxy S25 devices.

The exploit begins when an attacker lures a victim into clicking a malicious link. This triggers CVE-2025-21079, which manipulates the Samsung Members app to connect to a harmful website. Samsung Members, a preloaded app on many Galaxy smartphones, is then used to open the Samsung Account app, furthering the attack.

Breaking Down the Vulnerability Chain

Once the Samsung Account app is compromised, another vulnerability, CVE-2025-58486, redirects it to an attacker-controlled site. This site exploits an XSS vulnerability, CVE-2025-58487, to access Bixby. The researchers explained that Samsung Account’s special permissions allow it to interact with Bixby in ways not typically possible.

Gannon likened this interaction to having a key to a ‘side entrance’ of Bixby, facilitated by the Samsung Account app. The attack progresses with a Capsule, a hidden service within apps that Bixby uses to translate voice commands into tasks, potentially allowing attackers to control device functions and access sensitive data.

Impact and Response from Samsung

Gannon and Valsamaras demonstrated that once system-level permissions are gained, remote code execution becomes possible, effectively allowing complete control over the device. The exploit was verified on Samsung Galaxy S25, S24, and Flip 7 models.

Following the Pwn2Own competition, Samsung began issuing patches in November 2025 to mitigate these vulnerabilities, specifically targeting the Samsung Members and Samsung Account apps. However, concerns remain regarding older devices that might not receive updates.

Despite the patches, the researchers warned that the exploit chain could still affect devices with the necessary apps installed, raising questions about security on budget models. Samsung has yet to comment publicly on these findings.

Future Implications

This discovery highlights the ongoing challenges in mobile security, emphasizing the need for continuous vigilance and timely updates to protect against emerging threats. As technology evolves, so too must the strategies to safeguard it.

Security Week News Tags:Bixby, black hat, CVE-2025, Cybersecurity, mobile vulnerabilities, Pwn2Own, Samsung, security exploit, smartphone security, vulnerability patch

Post navigation

Previous Post: OpenAI Halts Poipet Scam Using ChatGPT in Fraud Schemes
Next Post: Fraudulent AI Token Sales Exploit Free Cloud Accounts

Related Posts

Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime Security Week News
38 Security Flaws Discovered in OpenEMR Software 38 Security Flaws Discovered in OpenEMR Software Security Week News
437,000 Impacted by Ascension Health Data Breach 437,000 Impacted by Ascension Health Data Breach Security Week News
Adobe Issues Urgent Update for Critical Software Flaws Adobe Issues Urgent Update for Critical Software Flaws Security Week News
Latest Android Update Fixes Zero-Day and 123 Vulnerabilities Latest Android Update Fixes Zero-Day and 123 Vulnerabilities Security Week News
Anubis Ransomware Packs a Wiper to Permanently Delete Files Anubis Ransomware Packs a Wiper to Permanently Delete Files Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark