Новости компьютерной безопасности:

  Latest News

PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access

С сайта: Vulnerability(cybersecuritynews.com)

PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access

Author: Abinaya

In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System.

The CVE-2026-0073 flaw in Android’s adbd daemon lets nearby threat actors remotely gain full shell access without victim interaction.

Unearthed by BARGHEST security researchers, this critical cryptographic breakdown completely shatters Android’s debugging trust model, transforming a standard developer tool into an invisible, weaponized backdoor.

Android Zero-Click PoC Released
The foundation of CVE-2026-0073 is a cryptographic logic error in the adbd_tls_verify_cert function of the auth.cpp file.

Modern wireless ADB connections rely on mutual TLS authentication to ensure that a connecting client is a previously paired and trusted host.

During this handshake, the system uses the EVP_PKEY_cmp API to compare the client’s certificate public key against authorized RSA keys stored on the device.

If an attacker supplies a non-RSA certificate, such as EC P-256 or Ed25519, the comparison API returns -1 to flag a cross-algorithm mismatch.

Because the underlying C++ implementation treats all non-zero integers as a boolean success, the daemon incorrectly validates the attacker’s mismatched certificate as a trusted host key.


While the logic flaw is straightforward, weaponizing it requires precise manipulation of protocol.

An attacker must first establish a TCP connection, successfully negotiate the STLS upgrade sequence, and then supply the malicious cross-algorithm certificate.

Once this authentication gate is bypassed, the attacker can resume ADB framing inside the encrypted tunnel to open a remote shell.

This grants the attacker execution privileges as the shell user, allowing them to bypass normal application sandboxes.

Consequently, threat actors can extract sensitive personal information, abuse package management to silently install malicious applications, and manipulate system settings to stage further device exploitation.

According to Barghest Research, the vulnerability mainly affects Android 14, 15, and 16 devices under specific state conditions.

Successful exploitation demands the following prerequisites:

  • Developer options are actively enabled on the target device.
  • Wireless debugging, or ADB over TCP, is exposed on the network.
  • The device trust store contains at least one previously paired RSA host key.
  • The attacker has adjacent network reachability to the device’s ADB TCP port 5555.

Device users and enterprise administrators must apply the May 2026 security patch immediately to resolve this critical flaw.

To proactively reduce attack surfaces, users should turn off wireless debugging on untrusted networks and revoke authorizations for unknown debugging hosts.

Turning off Developer options entirely when not in use is highly recommended to protect against automated local network exploitation attempts.



#Android #Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news

Оригинальная версия на сайте: PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.