Description
Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.
Published: 2026-09-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an improper export of Android application components in Samsung Mobile Bixby Touch prior to version 4.3.01.17. This flaw enables local attackers to read sensitive data that should have been protected by the component boundaries. Because the components are exposed, confidential information such as personal settings or usage data can be accessed without authorization. The weakness relates to the misuse of component visibility, resulting in an information disclosure.

Affected Systems

Affected vendor is Samsung Mobile and product Bixby Touch. All releases before version 4.3.01.17 are compromised. Devices that run any earlier build of Bixby Touch on Android are impacted.

Risk and Exploitability

The CVSS score is 6.9, reflecting medium severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers need local device access; the flaw is exploitible through the exported components, meaning the attacker can trigger the exposure by executing code within the app or using the exposed component path. The attack surface is limited to compromised or shared devices, but the risk remains notable for any device where local adversaries can operate.

Generated by OpenCVE AI on September 9, 2026 at 23:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Bixby Touch to version 4.3.01.17 or later so the component export flaw is fixed.
  • Disable or uninstall Bixby Touch on devices that do not require the assistant to reduce the attack surface.
  • Enable device security controls, such as lock screens and app sandboxing, and limit local administrator privileges to prevent local attackers from exploiting the vulnerable components.

Generated by OpenCVE AI on September 9, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung bixby
CPEs cpe:2.3:a:samsung:bixby:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung bixby
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile bixby
Vendors & Products Samsung Mobile
Samsung Mobile bixby

Wed, 09 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Improper export of Android application components in Bixby Touch allows local attackers to access sensitive information

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-926

Wed, 09 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Improper export of Android application components in Bixby Touch allows local attackers to access sensitive information
Weaknesses CWE-200

Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Bixby
Samsung Mobile Bixby
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-09-09T20:24:26.569Z

Reserved: 2025-12-11T01:33:35.830Z

Link: CVE-2026-21108

cve-icon Vulnrichment

Updated: 2026-09-09T20:23:45.179Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T05:17:23.253

Modified: 2026-09-23T20:24:57.550

Link: CVE-2026-21108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-926

    Improper Export of Android Application Components