Impact
Bixby exhibits incorrect default permissions prior to version 4.0.86.0, which results in an incorrect privilege assignment (CWE‑276). This flaw allows a local attacker to execute arbitrary commands with Bixby’s authority, potentially compromising the device’s integrity and confidentiality. It is an improper privilege elevation rather than a command injection or broad access‑control failure.
Affected Systems
Samsung Mobile Bixby versions earlier than 4.0.86.0 are affected. No additional vendor or product information is available.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, indicating high impact. The EPSS score of < 1% indicates a low but nonzero likelihood of exploitation, and it is not listed in the CISA KEV catalog. The attack vector is local, requiring an attacker with access to the device or Bixby service. Exploitation would grant arbitrary command execution with Bixby privileges, potentially leading to full system compromise.
OpenCVE Enrichment