CVE-2026-21055: High severity Samsung Bixby vulnerability
Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Android Bixbyto a version that resolves this vulnerability.Fixed in 4.0.70.8 - Compensating control
Mitigate local exploitation by limiting local user access (e.g., restrict who can access the device / remove unnecessary local accounts) until Bixby is upgraded to version 4.0.70.8.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21055?
CVE-2026-21055 has a severity rating of high, with a CVSS score of 8.5.
How do I fix CVE-2026-21055?
To mitigate CVE-2026-21055, users should upgrade Samsung Bixby to version 4.0.70.8 or later.
What kind of attacks can exploit CVE-2026-21055?
CVE-2026-21055 can be exploited by local attackers to execute arbitrary commands with Bixby privileges.
Which software is affected by CVE-2026-21055?
CVE-2026-21055 affects Samsung Bixby versions prior to 4.0.70.8.
When was CVE-2026-21055 published?
CVE-2026-21055 was published on July 10, 2026.