CVE Tools
Back to feed
Research Samsung Galaxy S25, S24, Flip 7 mobile Samsung rce

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

SecurityWeek·By Eduard Kovacs··3 min read
CVE Tools coverage

Two security researchers uncovered a series of vulnerabilities in Samsung software, including the virtual assistant Bixby, that could be exploited to remotely take control of Samsung Galaxy smartphones. At the Pwn2Own Ireland competition in October 2025, Dimitrios Valsamaras and Ken Gannon demonstrated how these flaws were chained together to compromise a Galaxy S25 device, earning them $50,000. Their full findings were later presented at the Black Hat conference. The exploit begins with a phishing-style attack through a malicious link sent via ads or messaging apps, leading to remote code execution and system-level access. Affected products include the Galaxy S25, S24, and Flip 7. Samsung issued patches in November and December 2025 to address the issues.