Skip to content
← All advisories
CVE-2026-21074zd-01high

Incorrect default permissions in Bixby allow a local attacker to run commands as Bixby

Bixby before 4.0.86.0 ships components with incorrect default permissions. A local attacker already running code on the device can reach them and execute arbitrary commands with Bixby's privilege, reading and modifying data that should be out of reach. No user interaction is needed.

Overview

Bixby ships components whose default permissions are set too broadly. Anything already running on the device — an installed application, or code reached through another bug — can use them to execute commands with Bixby's own privilege.

Samsung fixed it in 4.0.86.0 and published it in the August 2026 Security Maintenance Release.

Classification

Samsung assigned CWE-276 — Incorrect Default Permissions, and scored it 7.2 (High) under CVSS 4.0:

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Reading the vector:

AV:L Local — the attacker is already on the device, not reaching it over a network
AC:L No special conditions to get right
AT:P A precondition has to hold
PR:L Low privilege is enough to start
UI:N The victim does nothing
VC:H VI:H Full loss of confidentiality and integrity within Bixby's scope

The shape it describes: not remotely reachable, but once anything is on the device it needs almost nothing to escalate, and the victim never sees it happen.

Impact

Arbitrary command execution at Bixby's privilege level. Bixby is a system-level assistant with broad access to device state, so this is a meaningful step up for code that arrived with little privilege of its own.

Fix

Update to 4.0.86.0 or later. Samsung's advisory is linked in the references.

References