Researchers Cracked Samsung Phones Wide Open by Turning Bixby Against Its Own Device
A five-step exploit chain using Bixby, Samsung Members, and Samsung Account could hand a stranger complete control of your Galaxy phone. Patches are out, but older devices may still be exposed.

Key points
- Two researchers earned $50,000 at the Pwn2Own Ireland hacking competition in October 2025 by chaining five software flaws to fully take over a Samsung Galaxy S25.
- The attack begins with a single tap on a malicious link and ends with an attacker holding the highest level of control available on a consumer Android phone.
- Samsung Galaxy S25, S24, and Flip 7 handsets were all confirmed vulnerable.
- Samsung patched Samsung Members in November 2025 and Samsung Account in December 2025.
- Older Galaxy devices without those updates may still be at risk if the relevant apps are installed.
Two security researchers worked out how to completely take over a Samsung Galaxy phone by tricking three of its built-in apps into doing things they were never supposed to do. The technique won Dimitrios Valsamaras, a senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab, $50,000 at Pwn2Own Ireland in October 2025. They laid out the full details at Black Hat shortly after. Our Black Hat 2025 roundup flagged this talk as one worth watching.
How did the attack actually work?
The victim taps a link, perhaps inside a chat message or served by a malicious advertisement. One tap is enough to start a five-step chain.
First, a flaw tracked as CVE-2025-21079 forces Samsung Members, the pre-installed support app that ships on most mid-range and flagship Galaxy phones, to connect to an attacker-controlled website. That site then pushes the Samsung Account app, which links your phone to Samsung's services, to talk to a second attacker-owned server. Two further flaws, CVE-2025-58486 and CVE-2025-58487, let that server inject malicious code into Samsung Account and use it to open Bixby, Samsung's voice assistant.
Bixby is the key. Samsung Account holds a special permission to access a hidden entry point inside Bixby, so the attacker can use it as a borrowed keycard. "Think of it as a 'side entrance' and Samsung Account happens to be a key holder for the 'side entrance,'" Gannon told SecurityWeek.
Once inside Bixby, the researchers targeted Capsules: small background services built into apps that carry out Bixby's voice commands, acting like mini internal servers. Samsung normally limits access so only Bixby itself can instruct a Capsule. By reverse-engineering the Capsule system (taking apart the compiled code to understand how it works), Valsamaras and Gannon found a way to force Bixby to misuse those Capsules and hand the attacker system-level permissions, the absolute highest privilege available on a stock consumer Android device. Running arbitrary code from there was straightforward.
It's a pattern we've seen elsewhere. The RedHook Android trojan used a similar borrowed-privilege trick in July, promoting itself past normal app limits by abusing a debugging feature Android exposes to legitimate tools.
Should Galaxy owners be worried right now?
If your phone's current, probably not.
| What was fixed | When Samsung patched it |
|---|---|
| CVE-2025-21079 (Samsung Members) | November 2025 |
| CVE-2025-58486 (Samsung Account) | December 2025 |
| CVE-2025-58487 (Samsung Account XSS) | December 2025 |
Gannon and Valsamaras confirmed the exploit works on Galaxy S25, S24, and Flip 7 handsets. Flagship models ship with all the relevant apps pre-installed; budget models may not, which would stop the chain before it starts. Phones that haven't received the November or December updates remain exposed where those apps are present.
Check your settings for the latest security patch date and install pending updates now. Treat unexpected links in messaging apps or mobile ads with real suspicion.
Common questions
Do I need to do anything if I have a newer Samsung phone?
Install any pending software updates and confirm your security patch level is December 2025 or later. Once patched, the known exploit chain no longer works.
What if I have an older Galaxy that is no longer getting updates?
Older devices that don't receive security patches are at real, ongoing risk. Don't tap links from unknown senders in messaging apps, and weigh whether moving to a supported device makes sense for you.



