Description
Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.
Published: 2026-08-10
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Bixby exhibits incorrect default permissions prior to version 4.0.86.0, which results in an incorrect privilege assignment (CWE‑276). This flaw allows a local attacker to execute arbitrary commands with Bixby’s authority, potentially compromising the device’s integrity and confidentiality. It is an improper privilege elevation rather than a command injection or broad access‑control failure.

Affected Systems

Samsung Mobile Bixby versions earlier than 4.0.86.0 are affected. No additional vendor or product information is available.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.2, indicating high impact. The EPSS score of < 1% indicates a low but nonzero likelihood of exploitation, and it is not listed in the CISA KEV catalog. The attack vector is local, requiring an attacker with access to the device or Bixby service. Exploitation would grant arbitrary command execution with Bixby privileges, potentially leading to full system compromise.

Generated by OpenCVE AI on August 11, 2026 at 08:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Samsung Mobile Bixby to version 4.0.86.0 or later.
  • If an immediate upgrade is not feasible, restrict Bixby’s permissions or disable the Bixby service to eliminate local access.
  • Configure device security policies to enforce strict permission boundaries for Bixby and monitor for unauthorized command execution.

Generated by OpenCVE AI on August 11, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Incorrect Default Permissions in Samsung Bixby Allow Local Privilege Escalation

Tue, 11 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Incorrect Default Permissions in Bixby Allow Local Command Execution
Weaknesses CWE-284
CWE-77

Tue, 11 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile bixby
Vendors & Products Samsung Mobile
Samsung Mobile bixby

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Incorrect Default Permissions in Bixby Allow Local Command Execution
Weaknesses CWE-284
CWE-77

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Bixby
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-11T03:55:35.080Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21074

cve-icon Vulnrichment

Updated: 2026-08-10T17:13:57.435Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-10T09:17:20.893

Modified: 2026-08-18T15:04:46.610

Link: CVE-2026-21074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T08:30:16Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions