CyberRota Analysis
AI-GeneratedBixby versions prior to 4.0.86.0 have incorrect default permissions that allow local attackers to execute arbitrary commands with elevated privileges. This vulnerability poses a significant risk to users, as it can lead to unauthorized access and control over the device. Organizations utilizing Bixby should prioritize updating to the latest version to mitigate potential exploitation.
CVE
CVE-2026-21074
Severity
HIGH
CVSS
7.2
EPSS
0.10%
Original NVD Description
Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.