A $50,000 Exploit Chain Exposes Samsung Phones to Remote System-Level Compromise
Two security researchers have discovered a sophisticated exploit chain that can turn Samsung’s virtual assistant Bixby against its own users. The attack, which was demonstrated at the Pwn2Own Ireland hacking competition in October 2025 and detailed this week at the Black Hat conference, can remotely compromise system-level permissions on affected devices, granting an attacker complete control over the device.
Dimitrios Valsamaras, a senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab, developed the exploit chain that starts with a user clicking on a malicious link delivered via ads or messaging apps. This triggers a vulnerability in Samsung Members, an official user community app preloaded on many Galaxy smartphones, which forces the app to connect to a malicious website.
The malicious site then exploits another vulnerability to force the Samsung Account app to connect to an attacker-controlled website, where an XSS (cross-site scripting) vulnerability is used to open Bixby. The researchers explained that this is possible because the Samsung Account app has special permissions required to interact with a specific “entry point” in Bixby.
The next stage of the attack involves Bixby’s Capsule, a hidden background service inside an app that acts like a mini internal server. By reverse-engineering the Capsule infrastructure on Samsung phones, the researchers found a way to force Bixby to use various Capsules maliciously, allowing an attacker to exfiltrate sensitive data and achieve system-level permissions.
The exploit chain was successfully demonstrated on Samsung Galaxy S25, S24, and Flip 7 smartphones. While Samsung has patched the vulnerabilities, it’s unclear if older devices that may not have received the patches are still vulnerable.
This attack highlights the importance of keeping software up to date, even on high-end devices like flagship models. The fact that the researchers were able to exploit Bixby’s Capsule infrastructure and use it to achieve remote system-level compromise is particularly concerning, as it suggests that attackers may be able to find similar vulnerabilities in other apps.
As a result, users are advised to exercise caution when clicking on links or downloading apps from unknown sources. Additionally, Samsung users should ensure their devices are running the latest software versions and security patches to minimize the risk of such attacks.
Source: SecurityWeek — 2026-08-05