CVE-2026-21074
7.2Samsung · Bixby
A local privilege escalation vulnerability due to incorrect default permissions in Samsung Bixby allows an authenticated user to gain elevated privileges.
Executive summary
Samsung Bixby contains an incorrect default permissions vulnerability that could allow an authenticated local attacker to escalate their privileges within the mobile environment.
Vulnerability
This is an incorrect default permissions vulnerability (CWE-276) that requires a local attacker to have low privileges. The flaw allows an attacker to perform actions with elevated rights that should otherwise be restricted.
Business impact
Exploitation of this vulnerability could allow a malicious actor with local access to the device to compromise system integrity or access restricted data. With a CVSS score of 7.2, the vulnerability presents a significant risk to the security posture of Samsung mobile devices in enterprise environments.
Remediation
Immediate Action: Update the Samsung Bixby application to version 4.0.86.0 or later via the official app store or system update channel.
Proactive Monitoring: Monitor device security logs for signs of unauthorized privilege escalation or unusual application behavior.
Compensating Controls: Ensure device management policies (MDM) are enforced to limit the installation of untrusted applications that could serve as an initial vector for local access.
Exploitation status
Public Exploit Available: No (no confirmed public exploit found in curated sources).
Analyst recommendation
Security teams should ensure that all managed Samsung devices receive the latest system and application updates. Prioritizing this update is essential for maintaining the security of enterprise data stored on mobile devices and preventing local privilege escalation.