Vulnerability intelligence
CVE-2025-21079
Samsung Mobile Samsung Members
Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.
CVSS Score
7.1
High
EPSS — Exploit Probability
0.5%
Riskier than 44% of all CVEs · checked 2026-09-19
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Aug 5, 2026 · latest Aug 5, 2026
Coverage timeline
-
Researchers Exploit Bixby Flaw to Hijack Samsung Phone at Pwn2Ownwww.securityweek.com · Aug 5, 2026