Junglewise Threat Intelligence

CVE-2026-21108: Samsung Bixby Touch improper component export

CVE-2026-21108 · Severity: medium · CVSS 5.5 · Published 2026-09-09

Vendors: Samsung.

Executive brief

Bixby Touch is Samsung's voice and touch interface for mobile devices. This vulnerability allows local attackers to access sensitive information by exploiting improperly exported Android application components. An attacker with physical or local access to a device could bypass security restrictions to view or manipulate private data.

Technical details

The vulnerability is an improper export of Android application components in Bixby Touch prior to version 4.3.01.17. This allows local attackers to access sensitive information through exposed application components that should have been properly restricted. The attack requires local access to the device. The patch adds proper access control to restrict component exposure.

Affected products

  • Samsung Bixby Touch prior to 4.3.01.17

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Version 4.3.01.17 resolves the vulnerability

References

Related threats