logo

PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access

ID: 109b1bc8-6320-5b9b-9ebe-e5bcd5c6c886

STIX ID: report--109b1bc8-6320-5b9b-9ebe-e5bcd5c6c886

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Abinaya

...
...

Google's May 2026 Android Security Bulletin discloses CVE-2026-0073, a critical zero-click vulnerability in the Android adbd daemon's TLS certificate verification that can let nearby attackers gain an unauthenticated remote shell by supplying a cross-algorithm certificate; a PoC is available and mitigations include applying the May 2026 patch, disabling wireless debugging/ADB over TCP, revoking unknown debug authorizations, and disabling Developer options when not in use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.