CVE-2026-21055 is a local privilege and command-execution vulnerability in Samsung Bixby affecting versions prior to 4.0.70.8. The flaw is caused by improper export of Android application components, which exposes internal Bixby functionality to other local applications. By invoking these improperly exported components, a local attacker can trigger execution of arbitrary commands in the security context of Bixby. The issue stems from insecure Android component exposure rather than remote network attack surface, and the vulnerable condition is resolved in Bixby version 4.0.70.8.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small standalone Python PoC for CVE-2026-21055 affecting Samsung Bixby on Android. There are three files: a README describing the vulnerability and usage, analyze_components.py for manifest inspection, and exploit.py for active exploitation. The code is not part of a larger exploit framework. The main exploit capability is local privilege abuse through Android Intent delivery. exploit.py uses adb shell commands to query package metadata (dumpsys package, pm path), optionally list resolver-table entries for exported components, and send a crafted broadcast Intent with extras 'command' and 'output' to a presumed vulnerable Bixby receiver/service. If successful, the targeted Bixby component executes the supplied shell command under the Bixby app context and writes output to /data/local/tmp/bixby_poc_output, which the script then reads and deletes. The exploit supports operator-supplied commands, custom component names, custom actions, and a listing mode for reconnaissance. analyze_components.py is a helper/reconnaissance script rather than the exploit itself. It parses a decompiled AndroidManifest.xml or decompiles an APK with apktool, then enumerates exported activities, services, receivers, and providers. It flags components that are exported without permission guards, helping identify candidate attack surfaces for inter-app Intent abuse. Overall purpose: demonstrate that an improperly exported Samsung Bixby component can be reached by any local app and abused to execute arbitrary commands with Bixby privileges. Attack vector is local only; there are no remote network callbacks or C2 behaviors in the code. The PoC is operational because it includes a working command-execution flow, but payload customization is basic and hardcoded around adb/am broadcast semantics rather than a reusable framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.