CVE-2026-21055
HIGHSamsung Bixby < 4.0.70.8 - Local Arbitrary Command Execution via Improper Android Component Export
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-21055. PoCs published by Hunt-Benito.
AI-analyzed exploit summary This repository provides a functional proof-of-concept exploit for CVE-2026-21055, an improper export of Android components in Samsung Bixby (<4.0.70.8). The exploit leverages unprotected exported receivers to execute arbitrary commands with Bixby's system-level privileges via crafted Intents.
Description
Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.
Exploits (1)
This repository provides a functional proof-of-concept exploit for CVE-2026-21055, an improper export of Android components in Samsung Bixby (<4.0.70.8). The exploit leverages unprotected exported receivers to execute arbitrary commands with Bixby's system-level privileges via crafted Intents.
References (1)
Scores
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X