Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisorycredential-access-method

Samsung Galaxy S25 flaws exposed credentials and enabled script execution

Updated 3mo agoFirst seen Mar 23, 20263 sources

Samsung disclosed two Galaxy S25 vulnerabilities reported through Pwn2Own that could be triggered remotely with user interaction. One flaw, CVE-2025-58486 (ZDI-26-224 / ZDI-CAN-28456), affects the Samsung Account application and allows arbitrary script execution in the current WebView through a cross-site scripting issue caused by improper validation of user-supplied data. The bug was assigned a CVSS 6.3 score and was credited to Ken Gannon, 伊藤 剣 (@yogehi) of Mobile Hacking Lab, and Dimitrios Valsamaras (@Ch0pin).

A second issue, CVE-2025-58488 (ZDI-26-223 / ZDI-CAN-28331), affects the Smart Touch Call application and can disclose sensitive information, including stored credentials, because of insufficient protection around URL-parameter-driven functionality. That flaw received a CVSS 5.9 score and was credited to Interrupt Labs. In both cases, exploitation requires a victim to visit a malicious page or open a malicious file, and Samsung has released updates to remediate the vulnerabilities.

Share:
Samsung Galaxy S25 flaws exposed credentials and enabled script execution
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 23, 20263mo ago

ZDI publicly discloses two Samsung Galaxy S25 vulnerabilities

Zero Day Initiative publicly disclosed ZDI-26-223 and ZDI-26-224, covering CVE-2025-58488 and CVE-2025-58486 respectively. The disclosures described a Smart Touch Call credential exposure issue and a Samsung Account XSS flaw, both originally disclosed through Pwn2Own.

Samsung releases updates for two Galaxy S25 vulnerabilities

Samsung released fixes for both disclosed Galaxy S25 issues: the Smart Touch Call information disclosure flaw and the Samsung Account cross-site scripting flaw. The advisories state updates were available by the time of public disclosure.

Nov 20, 20257mo ago

Researchers report Samsung Account open redirect flaw to Samsung

A Samsung Galaxy S25 open redirect security bypass in the Samsung Account application was reported to Samsung. Tracked as CVE-2025-58487 and ZDI-26-225, the flaw could let unauthenticated attackers redirect users to malicious content and use that behavior to launch arbitrary exported Android activities.

ZDI-26-225 | Zero Day Initiative

Researchers report Samsung Account XSS flaw to Samsung

Ken Gannon, 伊藤 剣 (@yogehi) of Mobile Hacking Lab, and Dimitrios Valsamaras (@Ch0pin) reported a Samsung Galaxy S25 cross-site scripting flaw in the Samsung Account application to Samsung. The bug, later tracked as CVE-2025-58486 and ZDI-26-224, allowed arbitrary script execution in the current WebView context with user interaction.

Nov 18, 20257mo ago

Interrupt Labs reports Samsung Smart Touch Call info disclosure flaw

Interrupt Labs reported a Samsung Galaxy S25 vulnerability in the Smart Touch Call application to Samsung. The issue, later tracked as CVE-2025-58488 and ZDI-26-223, could expose stored credentials through improper protection of URL-parameter-driven functionality.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Samsung Galaxy S25 flaws exposed credentials and enabled script execution | Mallory