CVE Tools

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

SecurityWeekBy Eduard Kovacs

ResearchSamsung Galaxy S25, S24, Flip 7

Our summary

Two security researchers uncovered a series of vulnerabilities in Samsung software, including the virtual assistant Bixby, that could be exploited to remotely take control of Samsung Galaxy smartphones. At the Pwn2Own Ireland competition in October 2025, Dimitrios Valsamaras and Ken Gannon demonstrated how these flaws were chained together to compromise a Galaxy S25 device, earning them $50,000. Their full findings were later presented at the Black Hat conference. The exploit begins with a phishing-style attack through a malicious link sent via ads or messaging apps, leading to remote code execution and system-level access. Affected products include the Galaxy S25, S24, and Flip 7. Samsung issued patches in November and December 2025 to address the issues.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store