CVE-2026-21055

HIGH

Samsung Bixby < 4.0.70.8 - Local Arbitrary Command Execution via Improper Android Component Export

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-21055. PoCs published by Hunt-Benito.

AI-analyzed exploit summary This repository provides a functional proof-of-concept exploit for CVE-2026-21055, an improper export of Android components in Samsung Bixby (<4.0.70.8). The exploit leverages unprotected exported receivers to execute arbitrary commands with Bixby's system-level privileges via crafted Intents.

Description

Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.

Exploits (1)

github WORKING POC
by Hunt-Benito · pythonpoc
https://github.com/Hunt-Benito/samsung-bixby-command-execution-cve-2026-21055-improper-component-export

This repository provides a functional proof-of-concept exploit for CVE-2026-21055, an improper export of Android components in Samsung Bixby (<4.0.70.8). The exploit leverages unprotected exported receivers to execute arbitrary commands with Bixby's system-level privileges via crafted Intents.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Samsung Bixby (com.samsung.android.bixby.agent) versions < 4.0.70.8
No auth needed
Prerequisites: Local access to a Samsung device with USB debugging enabled · Bixby version < 4.0.70.8 · ADB access to the device
mistral-large-3 · analyzed Jul 12, 2026 Full analysis →

Scores

CVSS v4 8.5
EPSS 0.0017
EPSS Percentile 6.9%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (1)
Samsung Mobile/Bixby 4.0.70.8
Published Jul 10, 2026
Tracked Since Jul 10, 2026