Junglewise Threat Intelligence

CVE-2026-21033: Samsung Assistant arbitrary script execution in ExpressHomeWidgetReceiver

CVE-2026-21033 · Severity: info · CVSS 6.9 · Published 2026-06-05

Vendors: Samsung.

Executive brief

Samsung Assistant is a virtual assistant application used on Samsung mobile devices. A security flaw in how the application handles internal communications allows a malicious app installed on the same device to execute unauthorized scripts. This could lead to unauthorized actions being performed within the context of the assistant application, potentially compromising user data or device functionality.

Technical details

A vulnerability exists in the ExpressHomeWidgetReceiver component of the Samsung Assistant application due to an improperly exported Android component. This lack of proper access control allows a local, malicious application to interact with the receiver without the necessary permissions. An attacker can exploit this to execute arbitrary scripts within the context of the Samsung Assistant app. Samsung has addressed this in version 9.3.14 by implementing proper access control and restricting component visibility.

Affected products

  • Samsung Samsung Assistant prior to 9.3.14

Timeline

  • 2026-06-02: advisory: Samsung published the security bulletin.
  • 2026-06-05: disclosed: NVD published the CVE record.

References