CVE-2026-0073
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.
- Affected products
- Android
- Google Android
- = 14.0, 15.0, 16.0
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.5% (43th percentile)
- Weakness
- CWE-303
- NVD status
- Analyzed
- Published
- 2026-05-04
CVE-2026-0073 at NVD
23 known exploits for CVE-2026-0073
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN
CVE-2026-0073
CVE-2026-0073
CVE-2026-0073-Android-client-TLS-auth-bypass
CVE-2026-41091-PoC-Exploit
CVE-2026-0073
CVE-2026-0073-Android-adbd-authentication-bypass
CVE-2026-0073-PoC-Exploit
CVE-2026-41940-PoC-Exploit
poc-CVE-2026-0073
CVE-2026-41091-PoC-Exploit Full-PoCv2
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android
aetherion
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android
Exploit for Incorrect Implementation of Authentication Algorithm in Google Android