PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access
ID: 109b1bc8-6320-5b9b-9ebe-e5bcd5c6c886
STIX ID: report--109b1bc8-6320-5b9b-9ebe-e5bcd5c6c886
Feed Name: cybersecurityNews.com
Threat Score
Google's May 2026 Android Security Bulletin discloses CVE-2026-0073, a critical zero-click vulnerability in the Android adbd daemon's TLS certificate verification that can let nearby attackers gain an unauthenticated remote shell by supplying a cross-algorithm certificate; a PoC is available and mitigations include applying the May 2026 patch, disabling wireless debugging/ADB over TCP, revoking unknown debug authorizations, and disabling Developer options when not in use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
