
[ZDI-26-224|CVE-2025-58486] (Pwn2Own) Samsung Galaxy S25 Samsung Account Cross-Site Scripting Remote Code Execution Vulnerability (CVSS 6.3; Credit: Ken Gannon / 伊藤 剣 (@yogehi) of Mobile Hacking Lab, and Dimitrios Valsamaras (@Ch0pin)) https://www.zerodayinitiative.com/advisories/ZDI-26-224/
Post summary
ZDI issued an advisory for CVE-2025‑58486, a cross‑site scripting flaw in Samsung Galaxy S25 that can lead to remote code execution, with a CVSS score of 6.3 and a linked full report.
