CVE-2026-21074: Samsung Mobile Bixby
High severity, CVSS 7.2. EPSS: 0.1% chance of exploitation in the next 30 days.
Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.
Affected products
- Samsung Mobile Bixby: before 4.0.86.0 (fixed in 4.0.86.0)
Published 2026-08-10. Last modified 2026-08-18.