Samsung’s preinstalled companion apps can become a trust chain that hands over device control from one app to the next. In this case, a single click on a link was enough to make Samsung Members, Samsung Account, and Bixby work together in ways they were not meant to, ending at system-level permissions on a Galaxy S25.
Researchers chained CVE-2025-21079, CVE-2025-58486, and CVE-2025-58487 to force those app handoffs and reach a privileged Bixby entry point that only Samsung Account could access. They demonstrated the exploit at Pwn2Own Ireland and later presented the full chain at Black Hat, showing it against a Samsung Galaxy S25.
The practical risk is not just the first app a user opens. It is the trusted path between Samsung’s own apps, which can be abused to cross from a normal tap into full device control on flagship Galaxy phones.