Medium severity4.0NVD Advisory· Published Dec 2, 2025· Updated Jun 17, 2026
CVE-2025-58486
CVE-2025-58486
Description
Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <15.5.01.1
- Range: 15.5.01.1
Patches
Vulnerability mechanics
References
1- security.samsungmobile.com/serviceWeb.smsbnvdVendor Advisory
News mentions
3- ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More StoriesThe Hacker News · Aug 6, 2026
- How a $50,000 Exploit Chain Turned Bixby Against Samsung PhonesSecurityWeek · Aug 5, 2026
- ZDI-26-224: (Pwn2Own) Samsung Galaxy S25 Samsung Account Cross-Site Scripting Remote Code Execution VulnerabilityZero Day Initiative · Mar 23, 2026