Samsung Members/Samsung Account/Bixby app-handoff chain (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
A Samsung Members and Samsung Account app-handoff vulnerability chain involving CVE-2025-21079, CVE-2025-58486, and CVE-2025-58487 enabled remote system-level compromise on Galaxy devices. The chain used Bixby entry-point abuse and a malicious link delivered through ads or messaging apps to push a target through multiple app handoffs, with potential remote code execution after system privileges were obtained. Samsung had patched Members in November 2025 and Account in December 2025, reducing exposure for updated devices.
Related Happenings
ShinyHunters-linked Salesforce intrusion campaign
Campaign
H score45
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
ShinyHunters-linked Salesforce intrusion campaign
CampaignAbout this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
Timeline
-
05.08.2026 22:40 2 articles · 1h ago
Samsung Members/Samsung Account/Bixby app-handoff chain (multiple vulnerabilities)
Initial DisclosureAt Pwn2Own Ireland in October 2025, researchers showed that a malicious link could trigger a Samsung app-handoff chain on Galaxy phones. The proof of concept moved through Samsung Members, Samsung Account, and Bixby before reaching elevated device control.
Show sources
- How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones — www.securityweek.com — 05.08.2026 22:40
- How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones — www.securityweek.com — 05.08.2026 22:40