← back
CVE-2026-0073

CVE-2026-0073

CVSS 8.8 HIGHEPSS 0.5%CWE-303
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.8EPSS 0.5%KEV nãoPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
04 May 2026Published on NVD
09 May 2026Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Google · Android
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →