Impact
Improper export of Android application components in Samsung Mobile Bixby is a weakness that exploits improper input validation (CWE‑20) and insufficient access control (CWE‑284), allowing a local attacker to execute arbitrary commands with the same privileges granted to Bixby. This flaw effectively grants a user with local access to run shell commands, leading to privileged code execution.
Affected Systems
Samsung Mobile Bixby versions prior to 4.0.70.8 on all Samsung devices are impacted.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score of < 1% suggests a low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and once local, an attacker can leverage the Bixby privilege level to execute arbitrary commands.
OpenCVE Enrichment