How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
Vulnerability: Researchers chained vulnerabilities in Bixby and Samsung Account to achieve system-level compromise on Samsung devices, earning $50,000 at Pwn2Own Ireland 2025.
Deep Analysis and Expert Commentary
The exploit chain demonstrates a multi-stage attack leveraging Samsung's trusted apps as entry points. Initial access via a malicious link triggers a cascade of vulnerabilities, culminating in Bixby Capsule manipulation—a rarely explored attack surface. This highlights systemic risks in vendor-specific app integrations, particularly those with elevated permissions. The attack's success on flagship models (S25, S24, Flip 7) underscores the impact of preinstalled app dependencies. While patched, the lingering threat to unupdated devices necessitates proactive measures: disabling unused system apps, scrutinizing app permissions, and prioritizing updates for Samsung Members and Account apps. The research also reveals broader implications for virtual assistant security architectures, particularly around Capsule access controls.
Action Items
- Apply Samsung's November/December 2025 patches for Samsung Members and Account apps immediately
- Audit device app permissions, especially for Bixby and preinstalled Samsung services
- Educate users on risks of clicking unsolicited links, even from trusted sources
Original Article Brief Intro
SecurityWeek · 2026-08-05 · Vulnerability: Researchers chained vulnerabilities in Bixby and Samsung Account to achieve system-level compromise on Samsung devices, earning $50,000 at Pwn2Own Ireland 2025.
Related Terms and Notes
CVE IDs
- CVE-2025-21079
- CVE-2025-58486
- CVE-2025-58487
Malware Families
- Pwn2Own — Premier hacking competition where researchers demonstrate zero-day exploits against popular software and devices
Techniques / TTPs
- RCE
Context Notes
- Bixby
- Capsule — Bixby's background service architecture that handles command execution, normally restricted to Bixby-only access
- Exploit Chain
- Mobile Security
- Mobile Vulnerability
- Pwn2Own
- Remote Code Execution
- Samsung Bixby