Samsung Members/Samsung Account/Bixby app-handoff chain (multiple vulnerabilities)
Vulnerability
Updated: 05.08.2026 22:40
· First: 05.08.2026 22:40
· 📰 1 src / 1 articles
· H score: 28
A Samsung Members and Samsung Account app-handoff vulnerability chain involving CVE-2025-21079, CVE-2025-58486, and CVE-2025-58487 enabled remote system-level compromise on Galaxy devices. The chain used Bixby entry-point abuse and a malicious link delivered through ads or messaging apps to push a target through multiple app handoffs, with potential remote code execution after system privileges were obtained. Samsung had patched Members in November 2025 and Account in December 2025, reducing exposure for updated devices.