High severity7.1NVD Advisory· Published Nov 5, 2025· Updated Jun 17, 2026
CVE-2025-21079
CVE-2025-21079
Description
Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<5.5.01.3+ 1 more
- (no CPE)range: <5.5.01.3
- (no CPE)range: 5.5.01.3
Patches
Vulnerability mechanics
References
1- security.samsungmobile.com/serviceWeb.smsbnvdVendor Advisory
News mentions
4- ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More StoriesThe Hacker News · Aug 6, 2026
- How a $50,000 Exploit Chain Turned Bixby Against Samsung PhonesSecurityWeek · Aug 5, 2026
- ZDI-26-209: (Pwn2Own) Samsung Galaxy S25 Samsung Members Open Redirect Security Bypass VulnerabilityZero Day Initiative · Mar 16, 2026
- ZDI-26-210: (Pwn2Own) Samsung Galaxy S25 Samsung Members Security Feature Bypass VulnerabilityZero Day Initiative · Mar 16, 2026