• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

How a $50,000 Exploit Chain Turned Bixby In opposition to Samsung Telephones 

Admin by Admin
August 6, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


BLACK HAT – Two safety researchers discovered a technique to exploit vulnerabilities in Samsung software program, together with the digital assistant Bixby, to hack cell gadgets.

The analysis was carried out by Dimitrios Valsamaras, senior safety researcher at Microsoft, and Ken Gannon, head of cell analysis at Cellular Hacking Lab. 

Gannon and Valsamaras demonstrated the vulnerabilities on the Pwn2Own Eire hacking competitors in October 2025, the place they earned $50,000 after exploiting them to hack a Samsung Galaxy S25 gadget.

The researchers have now detailed their findings in a chat on the Black Hat convention, describing the vulnerabilities they found and the way they have been chained to realize distant system-level compromise. 

The exploit developed by Gannon and Valsamaras begins with an attacker tricking the focused person into clicking a hyperlink delivered by way of malicious adverts or a messaging utility. 

After the sufferer clicks on the hyperlink, a vulnerability tracked as CVE-2025-21079 is exploited to pressure Samsung Members to hook up with a malicious web site. Samsung Members is an official person neighborhood, diagnostics, and assist app that’s preloaded on many mid-range and flagship Galaxy smartphones. 

Commercial. Scroll to proceed studying.

The malicious web site then forces Samsung Members to open the Samsung Account app, which is designed to attach customers to Samsung companies. 

Subsequent, a special vulnerability, CVE-2025-58486, is used to pressure Samsung Account to hook up with an attacker-controlled web site. This web site then exploits an XSS vulnerability tracked as CVE-2025-58487 to pressure Samsung Account to open Bixby, the digital assistant that may deal with voice instructions, visible searches, and gadget automation routines.

The researchers informed SecurityWeek that that is attainable as a result of the Samsung Account app has a particular permission that’s required to work together with a particular ‘entry level’ in Bixby. 

“Consider it as a ‘facet entrance’ and Samsung Account occurs to be a key holder for the ‘facet entrance,’” defined Gannon.

The following stage of the assault entails a Capsule, a hidden background service inside an app that acts like a mini inside server. When customers situation a voice command, Bixby interprets the request and sends it to the app’s Capsule to carry out the precise job. As a result of Capsules can instantly management app features, Samsung restricts entry in order that usually solely Bixby is allowed to speak to them. 

Nevertheless, the researchers reverse-engineered the Capsule infrastructure on Samsung telephones and located a technique to pressure Bixby to make use of varied Capsules maliciously. 

This enabled an attacker to exfiltrate delicate knowledge and obtain system-level permissions on the Android gadget—the best privilege degree that may be achieved on a inventory client gadget. 

The researchers confirmed that after an attacker has obtained ‘system’ permissions, they’ll obtain distant code execution and take management of the gadget.

The researchers mentioned they efficiently reproduced the exploit on Samsung Galaxy S25, S24, and Flip 7 smartphones. 

Vulnerabilities patched by Samsung

Samsung began patching the vulnerabilities a couple of weeks after the Pwn2Own competitors. Particularly, the corporate rolled out patches for the Samsung Members utility in November 2025, stopping the exploit chain from being triggered by way of an internet browser or messaging app. Patches launched in December fastened the Samsung Account flaws.

The researchers informed SecurityWeek that the assault works on older Samsung gadgets, which can not have acquired the patches, however famous that the exploit requires the entire focused apps to be put in. Whereas flagship fashions include the apps preinstalled, it’s unclear if that applies to price range fashions as properly.

Samsung has not responded to SecurityWeek’s request for remark.

Associated: Eight-12 months-Outdated Samsung KNOX Flaw Uncovered Tens of millions of Galaxy Units to Kernel Assaults

Associated: What’s Hiding in Your Cellular Apps? Lookout MSEC Goals to Discover Out

Associated: New Exploit Bypasses Apple’s Boot Defenses, Impacts Tens of millions of iPhones

Tags: BixbyChainExploitphonesSamsungTurned
Admin

Admin

Next Post
OpenAI Didn’t Discover Its AI Brokers Utilizing a Message Board to Plan Their Hacking Spree

OpenAI Didn’t Discover Its AI Brokers Utilizing a Message Board to Plan Their Hacking Spree

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

My Analysis of the 6 Greatest Contact Middle Workforce Software program

My Analysis of the 6 Greatest Contact Middle Workforce Software program

October 16, 2025
Need to perceive the present state of AI? Try these charts.

Need to perceive the present state of AI? Try these charts.

April 13, 2026

Trending.

Backrooms director Kane Parsons explains the birds, the portals, and his sensible results

Backrooms director Kane Parsons explains the birds, the portals, and his sensible results

May 31, 2026
100 Most Costly Key phrases for Google Advertisements in 2026

100 Most Costly Key phrases for Google Advertisements in 2026

January 13, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
Random Forest Algorithm in Machine Studying With Instance

Random Forest Algorithm in Machine Studying With Instance

May 4, 2025
Parental Lock Code Puzzle Defined

Parental Lock Code Puzzle Defined

July 27, 2025

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Resident Evil’s Licker Popcorn Bucket Is Able to Take a Chew Out of Your Pockets

Resident Evil’s Licker Popcorn Bucket Is Able to Take a Chew Out of Your Pockets

August 6, 2026
OpenAI Didn’t Discover Its AI Brokers Utilizing a Message Board to Plan Their Hacking Spree

OpenAI Didn’t Discover Its AI Brokers Utilizing a Message Board to Plan Their Hacking Spree

August 6, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved