CVE-2026-0073
HIGH 8.8EPSS 0.5%
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.54% chance of exploitation in the next 30 days, 43th percentile
- Published
- 2026-05-04
- Updated
- 2026-05-05
Proof-of-concept exploits (14)
- SecTestAnnaQuinn/CVE-2026-0073-Android-adbd-authentication-bypass-POC82★ · 2026-05-05
- adityatelange/poc-CVE-2026-007365★ · 2026-05-06
- MartinPSDev/CVE-2026-0073-Android-ADBD-bypass-POC22★ · 2026-05-07
- 0xBlackash/CVE-2026-00735★ · 2026-05-07
- novaek/CVE-2026-0073-Research5★ · 2026-05-06
- unnaim/adbHijacker7★ · 2026-05-07
- xqi1337/poc-CVE-2026-00731★ · 2026-06-21
- ctn-Qvo/CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN3★ · 2026-06-27
- m00ddy/CVE-2026-0073-Android-client-TLS-auth-bypass0★ · 2026-05-27
- fredevsec/CVE-2026-00731★ · 2026-06-04
- aye468448-eng/CVE-2026-0073-Android-adbd-authentication-bypass0★ · 2026-08-21
- 0xbinder/CVE-2026-0073
- devtint/CVE-2026-0073
- tc4dy/CVE-2026-0073-PoC-Exploit