Impact
Bixby exhibits incorrect default permissions prior to version 4.0.86.0, enabling a local attacker to execute arbitrary commands with Bixby privileges. This flaw effectively allows the attacker to run code with elevated authority, potentially compromising the device’s integrity and confidentiality. The weakness aligns with improper access control and command injection vulnerabilities.
Affected Systems
Samsung Mobile Bixby versions earlier than 4.0.86.0 are affected. No additional vendor or product information is available in the current data.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, indicating a high potential impact. The EPSS score is not available, which leaves the likelihood of exploitation uncertain, while the absence from the CISA KEV catalog shows no known active exploitation. The attack vector is local, requiring an attacker who can interact with the device or Bixby service. Exploitation would grant arbitrary command execution at Bixby level, potentially leading to full system compromise.
OpenCVE Enrichment