Overview
Bixby ships components whose default permissions are set too broadly. Anything already running on the device — an installed application, or code reached through another bug — can use them to execute commands with Bixby's own privilege.
Samsung fixed it in 4.0.86.0 and published it in the August 2026 Security Maintenance Release.
Classification
Samsung assigned CWE-276 — Incorrect Default Permissions, and scored it 7.2 (High) under CVSS 4.0:
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Reading the vector:
AV:L |
Local — the attacker is already on the device, not reaching it over a network |
AC:L |
No special conditions to get right |
AT:P |
A precondition has to hold |
PR:L |
Low privilege is enough to start |
UI:N |
The victim does nothing |
VC:H VI:H |
Full loss of confidentiality and integrity within Bixby's scope |
The shape it describes: not remotely reachable, but once anything is on the device it needs almost nothing to escalate, and the victim never sees it happen.
Impact
Arbitrary command execution at Bixby's privilege level. Bixby is a system-level assistant with broad access to device state, so this is a meaningful step up for code that arrived with little privilege of its own.
Fix
Update to 4.0.86.0 or later. Samsung's advisory is linked in the references.