Bixby Vulnerability Chain: Malicious Link Could Give Attackers Control of Galaxy Devices
A chain of vulnerabilities in Samsung software allowed a malicious link to trigger remote compromise of a device. The attack was demonstrated at Pwn2Own
Illustrative image generated with AI
Attack Demonstrated on Galaxy S25, S24, and Flip 7
A chain of vulnerabilities in Samsung software allowed a malicious link to trigger remote compromise of a device. The attack was demonstrated at Pwn2Own Ireland in October 2025 by Microsoft’s Dimitrios Valsamaras and Ken Gannon of Mobile Hacking Lab.
The researchers earned $50,000 by compromising a Samsung Galaxy S25. They later reproduced the technique on a Galaxy S24 and Galaxy Flip 7, although it remains unclear which other models are vulnerable.
The issue was disclosed on August 5, 2026. Samsung began rolling out fixes several weeks after the demonstration.
The Chain Runs Through Samsung Members, Samsung Account, and Bixby
The attack requires the victim to open a link controlled by the attacker, delivered, for example, through malvertising or a messaging app. It is therefore not fully automatic, but the link can be disguised as legitimate content.
The technical sequence is as follows:
- CVE-2025-21079 tricks Samsung Members into connecting to a malicious website.
- The website forces Samsung Members to open Samsung Account.
- CVE-2025-58486 causes Samsung Account to connect to the attacker’s infrastructure.
- The CVE-2025-58487 XSS vulnerability allows Samsung Account to be instructed to open Bixby.
- A special permission granted to Samsung Account provides access to a specific assistant entry point.
- Capsules—the background services Bixby uses to process voice requests—are manipulated to perform unintended operations.
By reverse-engineering the Capsule infrastructure, the researchers were able to use these components as internal mini-servers. This allowed the attack chain to exfiltrate sensitive data and obtain system privileges.
Impact: Code Execution and Device Control
The system level is the highest privilege normally available on an unmodified consumer Android device. With this access, an attacker can execute code remotely and take control of the phone.
The operational impact is therefore critical, although the attack depends on three conditions: the victim opening the link, the target applications being installed, and the entire chain working as intended.
Samsung Members, Samsung Account, and Bixby are typically present on high-end Galaxy models. It is not known whether the same combination is available on budget devices or all older models. The exact software versions affected have not been disclosed.
Patches Released and Guidance for Users
Updates to Samsung Members released in November 2025 prevent the chain from being triggered through a web browser or messaging app. Fixes for Samsung Account were released in December 2025.
Users should:
- update the operating system;
- install updates for Samsung Members, Samsung Account, and Bixby;
- verify that patches are installed for all affected applications;
- avoid opening links from untrusted sources, unexpected messages, or suspicious advertisements.
Samsung did not respond to SecurityWeek’s request for comment.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2025-21079High7.1Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.
- CVE-2025-58486Medium4.0Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.
- CVE-2025-58487Medium4.0Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.




