Researchers from Microsoft and Mobile Hacking Lab chained multiple Samsung flaws to remotely compromise Galaxy devices through Bixby, Samsung Members, and Samsung Account. Samsung later patched the issues after the Pwn2Own Ireland demo, but older devices may still be at risk if the affected apps are installed. #Bixby #SamsungMembers #SamsungAccount #CVE-2025-21079 #CVE-2025-58486 #CVE-2025-58487 #SamsungGalaxyS25 #SamsungGalaxyS24 #Flip7
Keypoints
- Researchers chained Samsung app flaws to gain remote system-level access.
- The exploit began with a malicious link delivered through ads or messaging apps.
- CVE-2025-21079, CVE-2025-58486, and CVE-2025-58487 enabled the attack chain.
- The attack abused Samsung Members, Samsung Account, and Bixby entry points.
- Samsung patched the issues after Pwn2Own Ireland, but older devices may still be vulnerable.
Read More: https://www.securityweek.com/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones/