TWO security researchers demonstrated a method to exploit vulnerabilities in Samsung software, particularly through the Bixby virtual assistant, allowing them to hack Samsung mobile devices. Dimitrios Valsamaras from Microsoft and Ken Gannon from Mobile Hacking Lab showcased the exploit at the Pwn2Own Ireland competition in October 2025, earning $50,000.
Their attack involved tricking users into clicking malicious links that exploited specific vulnerabilities (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) to gain system-level permissions, enabling remote code execution and control over the device. Samsung has since patched these vulnerabilities, but older models may remain at risk.