At the forefront of mobile security discussions, two researchers have uncovered a significant vulnerability chain in Samsung’s software, including the virtual assistant Bixby. Their findings, which earned them $50,000, were demonstrated at the Pwn2Own Ireland hacking competition in October 2025.
Security Experts Reveal Exploit Details
Microsoft’s Dimitrios Valsamaras and Ken Gannon from Mobile Hacking Lab spearheaded the research. They showcased their discoveries at the Black Hat conference, detailing the method of linking various vulnerabilities to achieve a remote system-level breach of Samsung Galaxy S25 devices.
The exploit begins when an attacker lures a victim into clicking a malicious link. This triggers CVE-2025-21079, which manipulates the Samsung Members app to connect to a harmful website. Samsung Members, a preloaded app on many Galaxy smartphones, is then used to open the Samsung Account app, furthering the attack.
Breaking Down the Vulnerability Chain
Once the Samsung Account app is compromised, another vulnerability, CVE-2025-58486, redirects it to an attacker-controlled site. This site exploits an XSS vulnerability, CVE-2025-58487, to access Bixby. The researchers explained that Samsung Account’s special permissions allow it to interact with Bixby in ways not typically possible.
Gannon likened this interaction to having a key to a ‘side entrance’ of Bixby, facilitated by the Samsung Account app. The attack progresses with a Capsule, a hidden service within apps that Bixby uses to translate voice commands into tasks, potentially allowing attackers to control device functions and access sensitive data.
Impact and Response from Samsung
Gannon and Valsamaras demonstrated that once system-level permissions are gained, remote code execution becomes possible, effectively allowing complete control over the device. The exploit was verified on Samsung Galaxy S25, S24, and Flip 7 models.
Following the Pwn2Own competition, Samsung began issuing patches in November 2025 to mitigate these vulnerabilities, specifically targeting the Samsung Members and Samsung Account apps. However, concerns remain regarding older devices that might not receive updates.
Despite the patches, the researchers warned that the exploit chain could still affect devices with the necessary apps installed, raising questions about security on budget models. Samsung has yet to comment publicly on these findings.
Future Implications
This discovery highlights the ongoing challenges in mobile security, emphasizing the need for continuous vigilance and timely updates to protect against emerging threats. As technology evolves, so too must the strategies to safeguard it.
