Researchers disclosed a Samsung smartphone exploit chain that turned a malicious link into remote system-level compromise by chaining flaws in Samsung Members, Samsung Account, and Bixby. Demonstrated at Pwn2Own Ireland 2025 against a Galaxy S25 and later detailed at Black Hat 2026, the attack used CVE-2025-21079, CVE-2025-58486, and CVE-2025-58487 to pivot across Samsung apps and abuse Bixby’s Capsule infrastructure, enabling sensitive data theft, elevated privileges, and ultimately remote code execution on stock devices.
Samsung’s mobile security advisories show the affected ecosystem also included multiple high-severity weaknesses across Samsung software, including Samsung Members, Bixby wakeup, Samsung Gallery, Secure Folder, and libsavscmn, with impacts ranging from arbitrary file read/write and lock reset to memory corruption and code execution. Samsung said it patched the Samsung Members issue in November 2025 and the Samsung Account flaws in December 2025; the exploit chain was reproduced on Galaxy S25, S24, and Flip 7 devices, and researchers warned that older phones may remain vulnerable if they did not receive the updates.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The researchers later presented technical details of the Samsung smartphone exploit chain at Black Hat 2026. They described how a malicious link could abuse Samsung Members, Samsung Account, and Bixby Capsule infrastructure to exfiltrate data, gain system privileges, and achieve remote code execution.
Samsung released patches in December 2025 for the Samsung Account vulnerabilities used in the exploit chain. These fixes addressed the issues that let attackers pivot from Samsung Members into Samsung Account and then into Bixby.
Samsung released patches for the Samsung Members issue in November 2025. According to the researchers, these updates blocked triggering the exploit chain through a web browser or messaging app.
In October 2025, Dimitrios Valsamaras of Microsoft and Ken Gannon of Mobile Hacking Lab demonstrated an exploit chain against a Samsung Galaxy S25 at Pwn2Own Ireland. They earned $50,000 for chaining flaws in Samsung Members, Samsung Account, and Bixby to achieve remote system-level compromise.
Samsung's bulletin says the disclosed application vulnerabilities were reported over a period spanning April 2024 through April 2025. The affected components included Samsung Members, Bixby wakeup, Samsung Gallery, Bixby Vision, Samsung Flow, Secure Folder, PackageInstallerCN, AODService, Samsung Notes, PENUP, and libsavscmn.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcesecurityweek.com
Open sourcesecurity.samsungmobile.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.