From Samsung Account to RCE: A Journey to a Remote 0-Click Capability
Kaufi
OffensiveCon 2026 · Day 2 · Main Stage
In this compelling talk at OffensiveCon, Yuval Kaufman, known as Kalfy, a VP R&D at Radiant Research Labs, detailed an intricate journey culminating in a **remote zero-click capability** leading to Remote Code Execution (RCE) on Samsung Android devices. The research focused on exploiting vulnerabilities within the vast **Samsung Account ecosystem** and proprietary image processing mechanisms. Kalfy emphasized the methodical approach taken, navigating numerous challenges to chain seemingly disparate primitives into a potent attack chain.
AI review
Kaufman drops a fully realized zero-click RCE chain on Samsung devices — credential leakage via profile picture URL manipulation, notification silencing through a malformed FCM field, and exploitation of a proprietary Quram image codec that vendors thought they'd buried. Every primitive is original, the chain is elegant, and the live demo closes the argument. This is exactly what OffensiveCon exists for.