Junglewise Threat Intelligence

CVE-2026-21055: Samsung Bixby arbitrary command execution via improperly exported components

CVE-2026-21055 · Severity: info · CVSS 8.5 · Published 2026-07-10

Vendors: Samsung.

Executive brief

Samsung Bixby, a voice-controlled virtual assistant, contained a vulnerability that allowed other apps on the same device to interact with its internal components. A malicious application installed on the device could exploit this to execute commands with the elevated permissions assigned to Bixby. This could lead to unauthorized actions or access to user data managed by the assistant.

Technical details

A vulnerability exists in Samsung Bixby due to the improper export of Android application components (Activities, Services, or Receivers) without adequate access control. A local malicious application can interact with these exported components to trigger unintended functionality. This allows an attacker to execute arbitrary commands with the privileges of the Bixby application. The issue is resolved in version 4.0.70.8 by implementing proper access controls on the affected components.

Affected products

  • Samsung Bixby prior to 4.0.70.8

Timeline

  • 2026-07-07: advisory: Samsung published the security bulletin.
  • 2026-07-10: disclosed: CVE published to NVD.

References

Related threats