Samsung patched a Galaxy phone exploit chain that abused Samsung Members, Samsung Account, and Bixby for system-level compromise

Researchers showed that multiple flaws in Samsung’s mobile apps could be chained to take over Galaxy phones after a user clicked a malicious link. The chain used CVE-2025-21079 in Samsung Members plus CVE-2025-58486 and CVE-2025-58487 in Samsung Account to pivot into Bixby and abuse app 'Capsules' for data theft and system-level access on Galaxy S25, S24, and Flip 7 devices. Samsung says patches for Samsung Members shipped in November 2025 and Samsung Account fixes followed in December 2025.
Why it matters: Samsung users, especially on older devices that may not have received the fixes, could be exposed to full device compromise from a link-based attack. Users should install Samsung app and device updates immediately, and defenders should verify Samsung Members and Samsung Account are patched across managed fleets.

Sources

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
Eduard Kovacs 2026.08.05 100% relevant
This article establishes a distinct tracked story by publicly detailing the full exploit chain, affected Samsung apps, CVE IDs, and patched timeline for a high-impact Galaxy device compromise demonstrated at Pwn2Own and Black Hat.
← Back to all stories