How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

https://www.securityweek.com/wp-content/uploads/2026/06/Samsung-Android-Vulnerability.jpg

BLACK HAT –Two security researchers found a way to exploit vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices.

The research was conducted by Dimitrios Valsamaras, senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab.

Gannon and Valsamaras demonstrated the vulnerabilities at the Pwn2Own Ireland hacking competition in October 2025, where they earned $50,000 after exploiting them to hack a Samsung Galaxy S25 device.

The researchers have now detailed their findings in a talk at the Black Hat conference, describing the vulnerabilities they discovered and how they were chained to achieve remote system-level compromise.

The exploit developed by Gannon and Valsamaras starts with an attacker tricking the targeted user into clicking a link delivered via malicious ads or a messaging application.

After the victim clicks on the link, a vulnerability tracked as CVE-2025-21079 is exploited to force Samsung...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE