Medium severity4.0NVD Advisory· Published Dec 2, 2025· Updated Jun 17, 2026
CVE-2025-58487
CVE-2025-58487
Description
Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <15.5.01.1
- Range: 15.5.01.1
Patches
Vulnerability mechanics
References
1- security.samsungmobile.com/serviceWeb.smsbnvdVendor Advisory
News mentions
2- How a $50,000 Exploit Chain Turned Bixby Against Samsung PhonesSecurityWeek · Aug 5, 2026
- ZDI-26-225: (Pwn2Own) Samsung Galaxy S25 Samsung Account Open Redirect Security Bypass VulnerabilityZero Day Initiative · Mar 23, 2026