{"id":"CVE-2026-21055","title":"Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.","summary":"Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.","severity":"none","published":"2026-07-10","updated":"2026-07-11","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-21055","references":[{"url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=07","label":"mobile.security@samsung.com"}],"tags":["nvd","exploit-available"],"epss":0.00168,"epssPercentile":0.06561,"ingestedAt":"2026-07-11T20:15:25.970Z","exploits":{"github":1,"githubRepos":["https://github.com/Hunt-Benito/samsung-bixby-command-execution-cve-2026-21055-improper-component-export"],"checkedAt":"2026-09-21T15:28:26.616Z"},"exploitAvailable":true,"slug":"CVE-2026-21055","body":"## Overview\n\nImproper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":15,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":5004,"id":"CVE-2026-21055","ts":1788887227379,"field":"exploit_available","old":"false","new":"true"},{"seq":3887,"id":"CVE-2026-21055","ts":1788886358355,"field":"exploit_available","old":"true","new":"false"},{"seq":2709,"id":"CVE-2026-21055","ts":1788883023960,"field":"exploit_available","old":"false","new":"true"},{"seq":1738,"id":"CVE-2026-21055","ts":1788882428048,"field":"exploit_available","old":"true","new":"false"},{"seq":844,"id":"CVE-2026-21055","ts":1788881861354,"field":"exploit_available","old":"false","new":"true"}]}