How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A sophisticated exploit chain targeting vulnerabilities in Samsung's Members and Account applications has successfully turned Samsung's Bixby virtual assistant against its own phones. The chain, which involved multiple zero-day vulnerabilities, allowed attackers to gain control of the virtual assist

A recent attack on Samsung's flagship devices has highlighted the vulnerability of AI-powered virtual assistants like Bixby. The attack, which was attributed to a group of skilled hackers, involved exploiting multiple zero-day vulnerabilities in Samsung's Members and Account applications. The vulnerabilities, which were not publicly disclosed by Samsung, were discovered by researchers who had been tracking the group's activities. The exploit chain, which was estimated to be worth $50,000, allowed attackers to gain control of the virtual assistant and use it to send spam messages, make unauthorized purchases, and even remotely wipe the device. The attackers used the virtual assistant to send text messages to other users, including those who had not installed the Bixby app. The attack also targeted Samsung's Knox security platform, which is designed to protect sensitive data on the device. The attackers used the vulnerabilities to bypass the Knox security measures, allowing them to access the device's data and make unauthorized transactions. The attack was carried out by a group of hackers who had been tracking Samsung's Members and Account applications for several months. The group, which was identified as a sophisticated threat actor, had previously been linked to other high-profile attacks on Android devices. The attack highlights the need for greater security measures to be put in place to protect against AI-powered virtual assistants like Bixby. Samsung has since updated its security patches to address the vulnerabilities, but the attack has raised concerns about the long-term security of its devices. The incident has also sparked a debate about the responsibility of AI developers and the need for greater transparency in disclosing vulnerabilities. The researchers who discovered the vulnerabilities have called for greater cooperation between the cybersecurity industry and law enforcement agencies to better address the threat of AI-powered attacks.

Source: Snyk Blog