← BACK TO FEED
TAG

bixby1 articles

Bixby as a Backdoor: How Two Researchers Chained Samsung's Own Apps Into a Full Device Takeover

Two security researchers from Microsoft and Mobile Hacking Lab discovered a chain of vulnerabilities in Samsung software — including the Bixby virtual assistant, Samsung Members, and Samsung Account — that could allow attackers to achieve system-level control of a Samsung Galaxy device. The exploit begins with a malicious link and chains multiple CVEs to ultimately abuse Bixby's internal "Capsule" infrastructure, enabling data exfiltration and remote code execution. Samsung has since patched the flaws, but older devices that haven't received updates remain at risk; the researchers demonstrated the attack successfully on Galaxy S24, S25, and Flip 7 models and won $50,000 at the Pwn2Own Ireland competition.

6 Aug 2026