Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.
https://www.securityweek.com/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones/
https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=12