Executive brief
Samsung Bixby, a voice-controlled virtual assistant, contained a vulnerability that allowed other apps on the same device to interact with its internal components. A malicious application installed on the device could exploit this to execute commands with the elevated permissions assigned to Bixby. This could lead to unauthorized actions or access to user data managed by the assistant.
Technical details
A vulnerability exists in Samsung Bixby due to the improper export of Android application components (Activities, Services, or Receivers) without adequate access control. A local malicious application can interact with these exported components to trigger unintended functionality. This allows an attacker to execute arbitrary commands with the privileges of the Bixby application. The issue is resolved in version 4.0.70.8 by implementing proper access controls on the affected components.
Affected products
- Samsung Bixby prior to 4.0.70.8
Timeline
- 2026-07-07: advisory: Samsung published the security bulletin.
- 2026-07-10: disclosed: CVE published to NVD.