Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487)
Samsung Bixby Exploit Chain (TL-2026-1901), also tracked as Summoning Team S25 Exploit, is a critical-severity software vulnerability scored CVSS 8.1, first published 2026-08-05. It has no confirmed attribution, affects Samsung Samsung Members, references 3 CVEs (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487), maps to 16 MITRE ATT&CK techniques (T1005, T1059, T1071), and is covered by 9 detection rules and 4 indicators of compromise.
Key facts for TL-2026-1901
- Threat ID
- TL-2026-1901
- Also known as
- Summoning Team S25 Exploit, ZDI-26-209, ZDI-26-210, ZDI-26-224
- Severity
- CRITICAL
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-08-05
- Last reviewed
- 2026-08-05
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- consumer-electronics, enterprise, telecoms
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 4
Malware and tooling in Samsung Bixby Exploit Chain
Malware and tooling: Samsung Account, Samsung Bixby, Samsung Members
At Pwn2Own Ireland (October 2025), researchers Dimitrios Valsamaras (Microsoft) and Ken Gannon (Mobile Hacking Lab) demonstrated a chain of five vulnerabilities across Samsung Members, Samsung Account, and Bixby Capsule infrastructure that achieves system-level remote code execution on Samsung Galaxy S25, S24, and Flip 7 devices via a single malicious link. Samsung released patches in November and December 2025 for the Samsung Members and Samsung Account flaws respectively.
How Samsung Bixby Exploit Chain works
This exploit chain weaponizes Samsung's own pre-installed applications — Samsung Members (a support/diagnostics app), Samsung Account (a single-sign-on and account management service), and Bixby (the AI assistant) — against the device owner. The attack begins when a victim clicks a malicious link delivered via ads, messaging, or other web-based vectors.
The chain exploits three distinct CVEs. CVE-2025-21079 (CVSS 8.1, HIGH) in Samsung Members (< 5.5.01.3) is actually two related improper input validation flaws (ZDI-26-209 and ZDI-26-210): the first forces an open redirect to an attacker-controlled site, and the second exposes Samsung Members' WebView to a custom malicious URL, granting the attacker control over the app's navigation. From Samsung Members, the attacker leverages CVE-2025-58486 (improper input validation leading to XSS, CVSS 5.5, MEDIUM) and CVE-2025-58487 (improper authorization, CVSS 3.3, LOW) in Samsung Account (< 15.5.01.1) — the former injects arbitrary script into the Samsung Account WebView, while the latter launches arbitrary Android exported activities with Samsung Account's privileges.
The critical pivot point is that Samsung Account holds a special permission to interact with a specific entry point in Bixby — described by the researchers as a 'side entrance.' The XSS exploit forces Samsung Account to open Bixby through this privileged pathway. Once Bixby is opened under attacker control, the researchers exploit Bixby's Capsule infrastructure: hidden background services within apps that act as mini internal servers, normally accessible only to Bixby via voice commands. The researchers reverse-engineered this trust boundary and found a method to force Bixby to issue commands to Capsules in ways the system never intended, effectively weaponizing the assistant.
This Capsule abuse enables two critical capabilities: exfiltration of sensitive data stored on the device, and escalation to system-level permissions — the highest privilege level on a stock, unmodified consumer Android device — enabling full remote code execution and complete device takeover. The researchers successfully reproduced the chain on Samsung Galaxy S25, S24, and Flip 7 devices. Budget-model Galaxy devices may also be affected where the targeted pre-installed apps exist.
The findings were presented at Black Hat USA 2026 in a briefing titled 'One Click to System: Exploiting Bixby's Trust Model for Full Device Compromise.' No exploitation in the wild has been confirmed as of the advisory publication date. Samsung Members was patched in version 5.5.01.3 (November 2025 security update), and Samsung Account was patched in version 15.5.01.1 (December 2025 security update). A related but independently discovered Bixby vulnerability, CVE-2026-21055 (improper component export, CVSS 4.0 8.5), further demonstrates the attack surface of Bixby's exported components and was patched in Bixby 4.0.70.8.
MITRE ATT&CK techniques used in TL-2026-1901
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution; T1559 Inter-Process Communication
Command and Control
T1071 Application Layer Protocol
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
Defense Evasion
T1202 Indirect Command Execution; T1218 System Binary Proxy Execution
Impact
T1529 System Shutdown/Reboot; T1565 Data Manipulation
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
defense-impairment
Credential Access
T1555 Credentials from Password Stores
Exfiltration
Affected products and versions in Samsung Bixby Exploit Chain
- Samsung — Samsung Members
Vulnerable versions: <5.5.01.3
Fixed in: 5.5.01.3 - Samsung — Samsung Account
Vulnerable versions: <15.5.01.1
Fixed in: 15.5.01.1 - Samsung — Samsung Galaxy S25
Vulnerable versions: All versions without November/December 2025 SMR
Fixed in: SMR November 2025+ - Samsung — Samsung Galaxy S24
Vulnerable versions: All versions without November/December 2025 SMR
Fixed in: SMR November 2025+ - Samsung — Samsung Galaxy Z Flip 7
Vulnerable versions: All versions without November/December 2025 SMR
Fixed in: SMR November 2025+ - Samsung — Samsung Bixby
Vulnerable versions: <4.0.70.8
Fixed in: 4.0.70.8
Remediation for Samsung Bixby Exploit Chain
Patches
- Samsung Members 5.5.01.3 (November 2025 SMR)
- Samsung Account 15.5.01.1 (December 2025 SMR)
- Bixby 4.0.70.8 (July 2026 SMR — for CVE-2026-21055)
Immediate actions
- Update Samsung Members to version 5.5.01.3 or later via Galaxy Store
- Update Samsung Account to version 15.5.01.1 or later via Galaxy Store
- Apply Samsung November 2025 and December 2025 security maintenance releases on all Galaxy devices
- Verify monthly Samsung Security Bulletin compliance on all fleet devices
Workarounds
- Disable or uninstall Samsung Members if not required for support workflows
- Restrict installation of Samsung Account/Bixby on managed enterprise profiles
- Educate users not to click links from untrusted sources on Galaxy devices
- Block Samsung Members and Samsung Account network access via mobile firewall where feasible
Longer-term hardening
- Implement mobile device management (MDM) policies enforcing regular Samsung security updates
- Assess reliance on pre-installed Samsung applications for enterprise deployments
- Review Android intent-based attack surface for zero-trust posture on managed devices
- Deploy EDR/MDM capable of detecting anomalous inter-app IPC on Samsung devices
CVEs associated with Samsung Bixby Exploit Chain
CVE-2025-21079, CVE-2025-58486, CVE-2025-58487
Weaknesses (CWE) in Samsung Bixby Exploit Chain
CWE-20, CWE-79, CWE-285, CWE-926
Timeline of Samsung Bixby Exploit Chain
- Pavlo Fedorenko reported CVE-2025-21077, a related Samsung Email vulnerability, demonstrating Samsung's systemic Android intent-handling weaknesses
- Voorivex Team reported CVE-2025-58485, a Bixby Launcher uXSS vulnerability in Samsung Browser, highlighting the broader Bixby attack surface
- Exploit chain demonstrated at Pwn2Own Ireland 2025 (Day Two) by Ken Gannon (Mobile Hacking Lab) and Dimitrios Valsamaras (Summoning Team/Microsoft), earning $50,000 and 5 Master of Pwn points. Samsung Galaxy S25 compromised via chain of five bugs
- Samsung Account vulnerabilities (CVE-2025-58486, CVE-2025-58487) reported to Samsung via Zero Day Initiative coordination
- Samsung November 2025 Security Maintenance Release deployed. Samsung Members updated to version 5.5.01.3, patching CVE-2025-21079 via removal of unnecessary implementation
- Samsung Members vulnerabilities (CVE-2025-21079 / ZDI-26-209, ZDI-26-210) formally reported to Samsung by Gannon and Valsamaras via ZDI
- Samsung December 2025 Security Maintenance Release deployed. Samsung Account updated to version 15.5.01.1, patching both CVE-2025-58486 (improper input validation/XSS) and CVE-2025-58487 (improper authorization/activity launch)
- Voorivex Team awarded $2,700 bounty for CVE-2025-58485 (Bixby Launcher uXSS), a related Bixby attack vector
- ZDI publicly disclosed Samsung Members advisories ZDI-26-209 and ZDI-26-210 (both CVE-2025-21079) after 90-day embargo post-Pwn2Own
- ZDI publicly disclosed Samsung Account advisory ZDI-26-224 (CVE-2025-58486) after coordinated disclosure period
- CVE-2026-21055 published: Samsung Bixby improper component export (CVSS 4.0 8.5, HIGH) discovered by Tianyi Hu, allowing arbitrary command execution with Bixby privilege via exported CommandReceiver component. Patched in Bixby 4.0.70.8
- Black Hat USA 2026 briefing: 'One Click to System: Exploiting Bixby's Trust Model for Full Device Compromise' presented by Dimitrios Valsamaras and Ken Gannon, detailing the full exploit chain and Capsule reverse-engineering methodology
- SecurityWeek published detailed technical analysis of the exploit chain, confirming successful reproduction on Galaxy S25, S24, and Flip 7. No active in-the-wild exploitation reported
Sources cited for Samsung Bixby Exploit Chain
- How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
- ZDI-26-209: Samsung Galaxy S25 Samsung Members Open Redirect
- ZDI-26-210: Samsung Galaxy S25 Samsung Members Security Feature Bypass
- ZDI-26-224: Samsung Galaxy S25 Samsung Account Input Validation
- Samsung Mobile Security Bulletin — November 2025
- Samsung Mobile Security Bulletin — December 2025
- NVD — CVE-2025-21079 Detail
- NVD — CVE-2025-58486 Detail
- NVD — CVE-2025-58487 Detail
- Pwn2Own Ireland 2025 — Day Two Results
- BleepingComputer — Samsung Galaxy S25 Hacked at Pwn2Own Ireland 2025
- GitHub Advisory — CVE-2025-21079
- Black Hat USA 2026 — One Click to System: Exploiting Bixby's Trust Model
- CVE-2026-21055 PoC — Samsung Bixby Improper Component Export
Threats related to Samsung Bixby Exploit Chain
- AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + CWE-306 + CWE-78) in Microsoft AutoGen Studio MCP WebSocket Enables Browsing-Agent Hijack and Host RCE
- F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)
- Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via Cross-Agent Prompt Injection
Detection coverage for TL-2026-1901
As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1901 across Splunk SPL, Microsoft KQL and Sigma, covering 4 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.