Description
Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.
Published: 2026-07-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper export of Android application components in Samsung Mobile Bixby is a weakness that exploits improper input validation (CWE‑20) and insufficient access control (CWE‑284), allowing a local attacker to execute arbitrary commands with the same privileges granted to Bixby. This flaw effectively grants a user with local access to run shell commands, leading to privileged code execution.

Affected Systems

Samsung Mobile Bixby versions prior to 4.0.70.8 on all Samsung devices are impacted.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity. The EPSS score of < 1% suggests a low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and once local, an attacker can leverage the Bixby privilege level to execute arbitrary commands.

Generated by OpenCVE AI on July 28, 2026 at 08:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Samsung Mobile Bixby to version 4.0.70.8 or later
  • If upgrade is not possible, disable Bixby or remove the exported component definitions to prevent exposure
  • Audit the device manifest to ensure no other components are improperly exported that could enable privilege escalation

Generated by OpenCVE AI on July 28, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Bixby Improper Export Enables Local Attackers to Execute Arbitrary Commands
Weaknesses CWE-20
CWE-284

Wed, 22 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Bixby Improper Export Enables Local Attackers to Execute Arbitrary Commands
Weaknesses CWE-20
CWE-284

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Command Execution via Improper Export of Bixby Android Components
Weaknesses CWE-20
CWE-284

Thu, 16 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local Command Execution via Improper Export of Bixby Android Components
Weaknesses CWE-20
CWE-284

Wed, 15 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Bixby Android Components Allows Local Privileged Command Execution
Weaknesses CWE-20
CWE-284

Mon, 13 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Export of Bixby Android Components Allows Local Privileged Command Execution
Weaknesses CWE-20
CWE-284

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Enables Local Privilege Escalation in Samsung Bixby
Weaknesses CWE-20
CWE-284

Sun, 12 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Enables Local Privilege Escalation in Samsung Bixby
Weaknesses CWE-20
CWE-284

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper Component Export in Bixby
Weaknesses CWE-20
CWE-284

Fri, 10 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper Component Export in Bixby
Weaknesses CWE-20
CWE-284

Fri, 10 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile bixby
Vendors & Products Samsung Mobile
Samsung Mobile bixby

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Bixby
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-11T03:55:17.271Z

Reserved: 2025-12-11T01:33:35.820Z

Link: CVE-2026-21055

cve-icon Vulnrichment

Updated: 2026-07-10T11:39:21.969Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses

No weakness.