Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487)

Samsung Bixby Exploit Chain (TL-2026-1901), also tracked as Summoning Team S25 Exploit, is a critical-severity software vulnerability scored CVSS 8.1, first published 2026-08-05. It has no confirmed attribution, affects Samsung Samsung Members, references 3 CVEs (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487), maps to 16 MITRE ATT&CK techniques (T1005, T1059, T1071), and is covered by 9 detection rules and 4 indicators of compromise.

Key facts for TL-2026-1901

Threat ID
TL-2026-1901
Also known as
Summoning Team S25 Exploit, ZDI-26-209, ZDI-26-210, ZDI-26-224
Severity
CRITICAL
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-08-05
Last reviewed
2026-08-05
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
consumer-electronics, enterprise, telecoms
Target regions
Global
Detection rules
9
Indicators of compromise
4

Malware and tooling in Samsung Bixby Exploit Chain

Malware and tooling: Samsung Account, Samsung Bixby, Samsung Members

At Pwn2Own Ireland (October 2025), researchers Dimitrios Valsamaras (Microsoft) and Ken Gannon (Mobile Hacking Lab) demonstrated a chain of five vulnerabilities across Samsung Members, Samsung Account, and Bixby Capsule infrastructure that achieves system-level remote code execution on Samsung Galaxy S25, S24, and Flip 7 devices via a single malicious link. Samsung released patches in November and December 2025 for the Samsung Members and Samsung Account flaws respectively.

How Samsung Bixby Exploit Chain works

This exploit chain weaponizes Samsung's own pre-installed applications — Samsung Members (a support/diagnostics app), Samsung Account (a single-sign-on and account management service), and Bixby (the AI assistant) — against the device owner. The attack begins when a victim clicks a malicious link delivered via ads, messaging, or other web-based vectors.

The chain exploits three distinct CVEs. CVE-2025-21079 (CVSS 8.1, HIGH) in Samsung Members (< 5.5.01.3) is actually two related improper input validation flaws (ZDI-26-209 and ZDI-26-210): the first forces an open redirect to an attacker-controlled site, and the second exposes Samsung Members' WebView to a custom malicious URL, granting the attacker control over the app's navigation. From Samsung Members, the attacker leverages CVE-2025-58486 (improper input validation leading to XSS, CVSS 5.5, MEDIUM) and CVE-2025-58487 (improper authorization, CVSS 3.3, LOW) in Samsung Account (< 15.5.01.1) — the former injects arbitrary script into the Samsung Account WebView, while the latter launches arbitrary Android exported activities with Samsung Account's privileges.

The critical pivot point is that Samsung Account holds a special permission to interact with a specific entry point in Bixby — described by the researchers as a 'side entrance.' The XSS exploit forces Samsung Account to open Bixby through this privileged pathway. Once Bixby is opened under attacker control, the researchers exploit Bixby's Capsule infrastructure: hidden background services within apps that act as mini internal servers, normally accessible only to Bixby via voice commands. The researchers reverse-engineered this trust boundary and found a method to force Bixby to issue commands to Capsules in ways the system never intended, effectively weaponizing the assistant.

This Capsule abuse enables two critical capabilities: exfiltration of sensitive data stored on the device, and escalation to system-level permissions — the highest privilege level on a stock, unmodified consumer Android device — enabling full remote code execution and complete device takeover. The researchers successfully reproduced the chain on Samsung Galaxy S25, S24, and Flip 7 devices. Budget-model Galaxy devices may also be affected where the targeted pre-installed apps exist.

The findings were presented at Black Hat USA 2026 in a briefing titled 'One Click to System: Exploiting Bixby's Trust Model for Full Device Compromise.' No exploitation in the wild has been confirmed as of the advisory publication date. Samsung Members was patched in version 5.5.01.3 (November 2025 security update), and Samsung Account was patched in version 15.5.01.1 (December 2025 security update). A related but independently discovered Bixby vulnerability, CVE-2026-21055 (improper component export, CVSS 4.0 8.5), further demonstrates the attack surface of Bixby's exported components and was patched in Bixby 4.0.70.8.

MITRE ATT&CK techniques used in TL-2026-1901

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution; T1559 Inter-Process Communication

Command and Control

T1071 Application Layer Protocol

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

Defense Evasion

T1202 Indirect Command Execution; T1218 System Binary Proxy Execution

Impact

T1529 System Shutdown/Reboot; T1565 Data Manipulation

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

defense-impairment

T1553 Subvert Trust Controls

Credential Access

T1555 Credentials from Password Stores

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in Samsung Bixby Exploit Chain

  • Samsung — Samsung Members
    Vulnerable versions: <5.5.01.3
    Fixed in: 5.5.01.3
  • Samsung — Samsung Account
    Vulnerable versions: <15.5.01.1
    Fixed in: 15.5.01.1
  • Samsung — Samsung Galaxy S25
    Vulnerable versions: All versions without November/December 2025 SMR
    Fixed in: SMR November 2025+
  • Samsung — Samsung Galaxy S24
    Vulnerable versions: All versions without November/December 2025 SMR
    Fixed in: SMR November 2025+
  • Samsung — Samsung Galaxy Z Flip 7
    Vulnerable versions: All versions without November/December 2025 SMR
    Fixed in: SMR November 2025+
  • Samsung — Samsung Bixby
    Vulnerable versions: <4.0.70.8
    Fixed in: 4.0.70.8

Remediation for Samsung Bixby Exploit Chain

Patches

  • Samsung Members 5.5.01.3 (November 2025 SMR)
  • Samsung Account 15.5.01.1 (December 2025 SMR)
  • Bixby 4.0.70.8 (July 2026 SMR — for CVE-2026-21055)

Immediate actions

  • Update Samsung Members to version 5.5.01.3 or later via Galaxy Store
  • Update Samsung Account to version 15.5.01.1 or later via Galaxy Store
  • Apply Samsung November 2025 and December 2025 security maintenance releases on all Galaxy devices
  • Verify monthly Samsung Security Bulletin compliance on all fleet devices

Workarounds

  • Disable or uninstall Samsung Members if not required for support workflows
  • Restrict installation of Samsung Account/Bixby on managed enterprise profiles
  • Educate users not to click links from untrusted sources on Galaxy devices
  • Block Samsung Members and Samsung Account network access via mobile firewall where feasible

Longer-term hardening

  • Implement mobile device management (MDM) policies enforcing regular Samsung security updates
  • Assess reliance on pre-installed Samsung applications for enterprise deployments
  • Review Android intent-based attack surface for zero-trust posture on managed devices
  • Deploy EDR/MDM capable of detecting anomalous inter-app IPC on Samsung devices

CVEs associated with Samsung Bixby Exploit Chain

CVE-2025-21079, CVE-2025-58486, CVE-2025-58487

Weaknesses (CWE) in Samsung Bixby Exploit Chain

CWE-20, CWE-79, CWE-285, CWE-926

Timeline of Samsung Bixby Exploit Chain

  • Pavlo Fedorenko reported CVE-2025-21077, a related Samsung Email vulnerability, demonstrating Samsung's systemic Android intent-handling weaknesses
  • Voorivex Team reported CVE-2025-58485, a Bixby Launcher uXSS vulnerability in Samsung Browser, highlighting the broader Bixby attack surface
  • Exploit chain demonstrated at Pwn2Own Ireland 2025 (Day Two) by Ken Gannon (Mobile Hacking Lab) and Dimitrios Valsamaras (Summoning Team/Microsoft), earning $50,000 and 5 Master of Pwn points. Samsung Galaxy S25 compromised via chain of five bugs
  • Samsung Account vulnerabilities (CVE-2025-58486, CVE-2025-58487) reported to Samsung via Zero Day Initiative coordination
  • Samsung November 2025 Security Maintenance Release deployed. Samsung Members updated to version 5.5.01.3, patching CVE-2025-21079 via removal of unnecessary implementation
  • Samsung Members vulnerabilities (CVE-2025-21079 / ZDI-26-209, ZDI-26-210) formally reported to Samsung by Gannon and Valsamaras via ZDI
  • Samsung December 2025 Security Maintenance Release deployed. Samsung Account updated to version 15.5.01.1, patching both CVE-2025-58486 (improper input validation/XSS) and CVE-2025-58487 (improper authorization/activity launch)
  • Voorivex Team awarded $2,700 bounty for CVE-2025-58485 (Bixby Launcher uXSS), a related Bixby attack vector
  • ZDI publicly disclosed Samsung Members advisories ZDI-26-209 and ZDI-26-210 (both CVE-2025-21079) after 90-day embargo post-Pwn2Own
  • ZDI publicly disclosed Samsung Account advisory ZDI-26-224 (CVE-2025-58486) after coordinated disclosure period
  • CVE-2026-21055 published: Samsung Bixby improper component export (CVSS 4.0 8.5, HIGH) discovered by Tianyi Hu, allowing arbitrary command execution with Bixby privilege via exported CommandReceiver component. Patched in Bixby 4.0.70.8
  • Black Hat USA 2026 briefing: 'One Click to System: Exploiting Bixby's Trust Model for Full Device Compromise' presented by Dimitrios Valsamaras and Ken Gannon, detailing the full exploit chain and Capsule reverse-engineering methodology
  • SecurityWeek published detailed technical analysis of the exploit chain, confirming successful reproduction on Galaxy S25, S24, and Flip 7. No active in-the-wild exploitation reported

Sources cited for Samsung Bixby Exploit Chain

Threats related to Samsung Bixby Exploit Chain

Detection coverage for TL-2026-1901

As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1901 across Splunk SPL, Microsoft KQL and Sigma, covering 4 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats