Researchers Cracked Samsung Phones Wide Open by Turning Bixby Against Its Own Device
A five-step exploit chain using Bixby, Samsung Members, and Samsung Account could hand a stranger complete control of your Galaxy phone. Patches are out, but older devices may still be exposed.

Key points
- Two researchers earned $50,000 at the Pwn2Own Ireland hacking competition in October 2025 by using five linked software flaws to fully take over a Samsung Galaxy S25.
- The attack begins with a single tap on a malicious link and ends with an attacker having the highest level of control possible on an Android phone.
- Samsung Galaxy S25, S24, and Flip 7 handsets were all confirmed vulnerable.
- Samsung issued fixes for Samsung Members in November 2025 and for Samsung Account in December 2025.
- Older Galaxy devices that have not received those updates may still be at risk if they have the relevant apps installed.
Two security researchers worked out how to completely take over a Samsung Galaxy phone by tricking three of its built-in apps into doing things they were never supposed to do. The technique won Dimitrios Valsamaras, a senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab, $50,000 at Pwn2Own Ireland in October 2025. They laid out the full details at the Black Hat security conference shortly after.
How did the attack actually work?
The victim just taps a link, perhaps inside a chat message or served up by a malicious advertisement. That single tap is enough to set a five-step chain in motion.
First, a flaw tracked as CVE-2025-21079 forces Samsung Members, the pre-installed support and community app that ships on most mid-range and flagship Galaxy phones, to connect to a website the attacker controls. That site then pushes the Samsung Account app, which links your phone to Samsung's services, to talk to a second attacker-owned server. A pair of further flaws, CVE-2025-58486 and CVE-2025-58487, allow that server to inject malicious code into Samsung Account and use it to open Bixby, Samsung's voice assistant.
Bixby is the key. Because Samsung Account holds a special permission to access a hidden entry point inside Bixby, the attacker can use it as a kind of borrowed keycard. "Think of it as a 'side entrance' and Samsung Account happens to be a key holder for the 'side entrance,'" Gannon told SecurityWeek.
Once inside Bixby, the researchers targeted something called Capsules: small background mini-servers built into apps that carry out Bixby's voice commands. Samsung normally limits access so only Bixby itself can instruct a Capsule. By reverse-engineering (that is, dismantling and studying the code to understand how it works) the Capsule system, Valsamaras and Gannon found a way to force Bixby to misuse those Capsules and hand the attacker system-level permissions, the absolute highest level of control available on a standard consumer Android phone. From there, running any code they liked on the device was straightforward.
Should Galaxy owners be worried right now?
If your phone is up to date, probably not. The patches are already out.
| What was fixed | When Samsung patched it |
|---|---|
| CVE-2025-21079 (Samsung Members) | November 2025 |
| CVE-2025-58486 (Samsung Account) | December 2025 |
| CVE-2025-58487 (Samsung Account XSS) | December 2025 |
The researchers confirmed the exploit works on Galaxy S25, S24, and Flip 7 handsets. Flagship models come with all the relevant apps pre-installed; budget models may not, which would make the attack impossible to complete on those devices. Older phones that have not received the November or December security updates remain exposed if the apps are present.
Check your phone's settings for the latest security patch date and install any pending updates now. Be cautious about tapping links sent through messaging apps or shown in mobile advertisements, especially ones that feel unexpected or out of context.
Common questions
Do I need to do anything if I have a newer Samsung phone?
Install any pending software updates and confirm your security patch level is December 2025 or later. Once patched, the known exploit chain no longer works.
What if I have an older Galaxy that is no longer getting updates?
Older devices that no longer receive security patches are at real, ongoing risk. Avoid tapping links from unknown senders inside messaging apps, and consider whether upgrading to a supported device is practical for you.



