Bixby Vulnerability Chain: Malicious Link Could Give Attackers Control of Galaxy Devices

A chain of vulnerabilities in Samsung software allowed a malicious link to trigger remote compromise of a device. The attack was demonstrated at Pwn2Own

Bixby Vulnerability Chain: Malicious Link Could Give Attackers Control of Galaxy Devices
Vulnerabilities

Illustrative image generated with AI

Attack Demonstrated on Galaxy S25, S24, and Flip 7

A chain of vulnerabilities in Samsung software allowed a malicious link to trigger remote compromise of a device. The attack was demonstrated at Pwn2Own Ireland in October 2025 by Microsoft’s Dimitrios Valsamaras and Ken Gannon of Mobile Hacking Lab.

The researchers earned $50,000 by compromising a Samsung Galaxy S25. They later reproduced the technique on a Galaxy S24 and Galaxy Flip 7, although it remains unclear which other models are vulnerable.

The issue was disclosed on August 5, 2026. Samsung began rolling out fixes several weeks after the demonstration.

The Chain Runs Through Samsung Members, Samsung Account, and Bixby

The attack requires the victim to open a link controlled by the attacker, delivered, for example, through malvertising or a messaging app. It is therefore not fully automatic, but the link can be disguised as legitimate content.

The technical sequence is as follows:

  1. CVE-2025-21079 tricks Samsung Members into connecting to a malicious website.
  2. The website forces Samsung Members to open Samsung Account.
  3. CVE-2025-58486 causes Samsung Account to connect to the attacker’s infrastructure.
  4. The CVE-2025-58487 XSS vulnerability allows Samsung Account to be instructed to open Bixby.
  5. A special permission granted to Samsung Account provides access to a specific assistant entry point.
  6. Capsules—the background services Bixby uses to process voice requests—are manipulated to perform unintended operations.

By reverse-engineering the Capsule infrastructure, the researchers were able to use these components as internal mini-servers. This allowed the attack chain to exfiltrate sensitive data and obtain system privileges.

Impact: Code Execution and Device Control

The system level is the highest privilege normally available on an unmodified consumer Android device. With this access, an attacker can execute code remotely and take control of the phone.

The operational impact is therefore critical, although the attack depends on three conditions: the victim opening the link, the target applications being installed, and the entire chain working as intended.

Samsung Members, Samsung Account, and Bixby are typically present on high-end Galaxy models. It is not known whether the same combination is available on budget devices or all older models. The exact software versions affected have not been disclosed.

Patches Released and Guidance for Users

Updates to Samsung Members released in November 2025 prevent the chain from being triggered through a web browser or messaging app. Fixes for Samsung Account were released in December 2025.

Users should:

  • update the operating system;
  • install updates for Samsung Members, Samsung Account, and Bixby;
  • verify that patches are installed for all affected applications;
  • avoid opening links from untrusted sources, unexpected messages, or suspicious advertisements.

Samsung did not respond to SecurityWeek’s request for comment.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →