BLACK HAT – Two safety researchers discovered a technique to exploit vulnerabilities in Samsung software program, together with the digital assistant Bixby, to hack cell gadgets.
The analysis was carried out by Dimitrios Valsamaras, senior safety researcher at Microsoft, and Ken Gannon, head of cell analysis at Cellular Hacking Lab.
Gannon and Valsamaras demonstrated the vulnerabilities on the Pwn2Own Eire hacking competitors in October 2025, the place they earned $50,000 after exploiting them to hack a Samsung Galaxy S25 gadget.
The researchers have now detailed their findings in a chat on the Black Hat convention, describing the vulnerabilities they found and the way they have been chained to realize distant system-level compromise.
The exploit developed by Gannon and Valsamaras begins with an attacker tricking the focused person into clicking a hyperlink delivered by way of malicious adverts or a messaging utility.
After the sufferer clicks on the hyperlink, a vulnerability tracked as CVE-2025-21079 is exploited to pressure Samsung Members to hook up with a malicious web site. Samsung Members is an official person neighborhood, diagnostics, and assist app that’s preloaded on many mid-range and flagship Galaxy smartphones.
The malicious web site then forces Samsung Members to open the Samsung Account app, which is designed to attach customers to Samsung companies.
Subsequent, a special vulnerability, CVE-2025-58486, is used to pressure Samsung Account to hook up with an attacker-controlled web site. This web site then exploits an XSS vulnerability tracked as CVE-2025-58487 to pressure Samsung Account to open Bixby, the digital assistant that may deal with voice instructions, visible searches, and gadget automation routines.
The researchers informed SecurityWeek that that is attainable as a result of the Samsung Account app has a particular permission that’s required to work together with a particular ‘entry level’ in Bixby.
“Consider it as a ‘facet entrance’ and Samsung Account occurs to be a key holder for the ‘facet entrance,’” defined Gannon.
The following stage of the assault entails a Capsule, a hidden background service inside an app that acts like a mini inside server. When customers situation a voice command, Bixby interprets the request and sends it to the app’s Capsule to carry out the precise job. As a result of Capsules can instantly management app features, Samsung restricts entry in order that usually solely Bixby is allowed to speak to them.
Nevertheless, the researchers reverse-engineered the Capsule infrastructure on Samsung telephones and located a technique to pressure Bixby to make use of varied Capsules maliciously.
This enabled an attacker to exfiltrate delicate knowledge and obtain system-level permissions on the Android gadget—the best privilege degree that may be achieved on a inventory client gadget.
The researchers confirmed that after an attacker has obtained ‘system’ permissions, they’ll obtain distant code execution and take management of the gadget.
The researchers mentioned they efficiently reproduced the exploit on Samsung Galaxy S25, S24, and Flip 7 smartphones.
Vulnerabilities patched by Samsung
Samsung began patching the vulnerabilities a couple of weeks after the Pwn2Own competitors. Particularly, the corporate rolled out patches for the Samsung Members utility in November 2025, stopping the exploit chain from being triggered by way of an internet browser or messaging app. Patches launched in December fastened the Samsung Account flaws.
The researchers informed SecurityWeek that the assault works on older Samsung gadgets, which can not have acquired the patches, however famous that the exploit requires the entire focused apps to be put in. Whereas flagship fashions include the apps preinstalled, it’s unclear if that applies to price range fashions as properly.
Samsung has not responded to SecurityWeek’s request for remark.
Associated: Eight-12 months-Outdated Samsung KNOX Flaw Uncovered Tens of millions of Galaxy Units to Kernel Assaults
Associated: What’s Hiding in Your Cellular Apps? Lookout MSEC Goals to Discover Out
Associated: New Exploit Bypasses Apple’s Boot Defenses, Impacts Tens of millions of iPhones









