CVE-2026-0073
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to re…
Beschreibung
In `adbd_tls_verify_cert` von `auth.cpp` gibt es eine mögliche Umgehung der gegenseitigen Authentifizierung über WLAN-ADB aufgrund eines Logikfehlers im Code. Dies könnte zu einer Fernausführung (proximal/adjazenter) als Shell-Benutzer ohne zusätzliche Ausführungsrechte führen. Eine Benutzereingabe ist für die Ausnutzung nicht erforderlich.
Metriken
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
android
platform/packages/modules/adb14
android
platform/packages/modules/adb14:0
android
platform/packages/modules/adb15
android
platform/packages/modules/adb15:0
android
platform/packages/modules/adb16
android
platform/packages/modules/adb16:0
android
platform/packages/modules/adb16-qpr2
android
platform/packages/modules/adb16-qpr2:0
android
platform/packages/modules/adb16-qpr2-next
android
platform/packages/modules/adb16-qpr2-next:0
Quellen & Referenzen
Verknüpfte Empfehlungen
- sans-atrisk2026-05-21 00:00 UTCFwd: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 20
- sans-atrisk2026-05-14 00:00 UTCFwd: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 19
- sans-newsbites-mail2026-05-05 00:00 UTCLatvian National Sentenced in Connection with Providing Advice to Multiple Ransomware Groups