# A Trusted Shortcut Through Samsung's Own Apps Handed Attackers System-Level Control
The attack didn't need a zero-day in the Android kernel. It didn't require physical access, a sophisticated phishing campaign, or months of persistent foothold-building. It needed a malicious link, a few preloaded Samsung apps, and a virtual assistant that trusted the wrong caller.
That's the story Microsoft's Dimitrios Valsamaras and Mobile Hacking Lab's Ken Gannon told at Black Hat this week — one that earned them $50,000 at Pwn2Own Ireland last October and demonstrated full system-level compromise of a Samsung Galaxy S25 with nothing more than a well-crafted URL.
## How the Chain Actually Works
The exploit threads through Samsung's own privileged app ecosystem like someone walking hallway to hallway using a master keycard they picked up at reception.
It starts simply: the victim clicks a link. That link could arrive through a malicious ad network or a message from a compromised contact — both are realistic delivery vectors with no user-permission gates in the way. The link exploits CVE-2025-21079, a flaw in Samsung Members that forces the support and community app to connect to an attacker-controlled website. Samsung Members is preloaded on most mid-range and flagship Galaxy devices, so the attack surface isn't narrow.
From there, the malicious website forces Samsung Members to open Samsung Account — the identity hub that ties users to Samsung's broader services ecosystem. A second flaw, CVE-2025-58486, redirects Samsung Account to another attacker-controlled site, which then delivers the third punch: an XSS payload via CVE-2025-58487. Cross-site scripting in a native app sounds almost anachronistic, but Samsung Account's WebView surfaces were not locked down tightly enough to stop it.
Here's where it gets clever. Samsung Account holds a special, undocumented permission — what Gannon describes as a key to a "side entrance" into Bixby. That permission exists because Samsung's own apps need it: Samsung Account has to be able to invoke Bixby for legitimate automation and account-linked routines. The researchers didn't manufacture this trust relationship — they found it already there and learned how to walk through it from the wrong direction.
## Weaponizing the Voice Assistant's Internal Infrastructure
Most people think of Bixby as the thing that mishears "remind me to call Mom" and sets a timer instead. The underlying architecture is more complex.
When a user issues a voice command, Bixby parses the intent and forwards it to a Capsule — a hidden background service embedded inside an app that functions as a miniature internal server. Capsules are how apps expose functionality to Bixby: a music app exposes play/pause/skip; a maps app exposes navigation. Samsung restricts Capsule access so that, in theory, only Bixby can invoke them.
Valsamaras and Gannon reverse-engineered that Capsule infrastructure and found a way to coerce Bixby — once they'd injected into it via the Samsung Account XSS — into issuing arbitrary Capsule commands on their behalf. Since Capsules can directly manipulate app functions and interact with system-level APIs, this gave the researchers a path to system privileges on Android: the highest tier available on a stock consumer device, above even most factory-installed apps.
From system, they demonstrated remote code execution. The full chain — link click to total device control — worked on Galaxy S25, S24, and Flip 7 hardware.
## Patches Exist, But Reach Is the Problem
Samsung responded faster than its historical average. Patches for the Samsung Members flaw shipped in November 2025, cutting off the initial entry point through browsers and messaging apps. Samsung Account fixes followed in December. On an actively patched flagship, this specific chain is closed.
The uncomfortable word is "actively." Samsung's update distribution is famously uneven across its sprawling device lineup. The researchers confirmed the attack remains viable on older Galaxy devices that haven't received the patches. They also noted the full chain requires all the affected apps to be installed — a constraint that's automatically satisfied on most flagship and mid-range models, where Samsung Members, Samsung Account, and Bixby ship preloaded with no opt-out.
Budget models are a genuine unknown. If they ship without Bixby or Samsung Members, one or more links in the chain break. If they ship with everything, and updates are slow or halted, those devices remain exposed.
---
## HackWire Analysis
What this research illustrates isn't a flaw in Samsung's patching — it's a structural problem with how Android OEMs build privileged app ecosystems on top of a permission model designed for third-party apps.
Samsung's apps operate inside a web of inter-app trust relationships that Android's standard permission model doesn't surface to users or security teams. Samsung Account holding a special key to Bixby's internals isn't a bug — it's a design feature. The researchers didn't create that trust relationship; they found it and traversed it backwards. That's a much harder class of problem to solve than fixing a specific CVE, because the same pattern almost certainly exists in other Samsung apps, and likely in equivalent OEM stacks at LG (before its exit), Xiaomi, OPPO, and others who build deep software integrations on Android.
The Capsule architecture deserves more attention than it's getting. Samsung built an internal microservices layer — apps expose endpoints that Bixby calls, just like an internal API. The implicit assumption was that the only valid caller would be Bixby itself. That assumption didn't survive contact with attackers who could inject into Bixby from Samsung Account's WebView. Any similarly privileged caller that loads untrusted web content is potentially the same entry point somewhere else in Samsung's ecosystem.
For enterprise defenders managing Galaxy device fleets — and Samsung is genuinely enterprise-relevant at this point — the practical read is straightforward: audit whether your MDM enforces security patch levels for Samsung system apps specifically, not just the Android OS version. The two track independently. A device running the latest Android security patch level may still be sitting on November or December 2024 versions of Samsung Members or Samsung Account, which means it's exposed.
The $50,000 Pwn2Own prize was fair. This was surgical, original research that required deep knowledge of Samsung's proprietary app architecture. It's the kind of work that only happens when researchers are given enough time and incentive to actually understand a target rather than fuzz it until something breaks.
— HackWire Editorial
---
## Related Coverage