CVE-2026-0073

HIGH

Google Android <16-qpr2 - Auth Bypass

Title source: llm
STIX 2.1

Description

In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploits (10)

nomisec FAILED 3 stars
by SecTestAnnaQuinn · poc
https://github.com/SecTestAnnaQuinn/CVE-2026-0073-Android-adbd-authentication-bypass-POC
nomisec SCANNER 1 stars
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-0073
nomisec WORKING POC 1 stars
by MartinPSDev · poc
https://github.com/MartinPSDev/CVE-2026-0073-Android-ADBD-bypass-POC
nomisec WORKING POC 1 stars
by devtint · poc
https://github.com/devtint/CVE-2026-0073
nomisec WORKING POC 1 stars
by adityatelange · poc
https://github.com/adityatelange/poc-CVE-2026-0073
github WORKING POC
by unnaim · pythonpoc
https://github.com/unnaim/adbHijacker
nomisec SUSPICIOUS
by CryptReaper12 · poc
https://github.com/CryptReaper12/CVE-2026-0073
nomisec FAILED
by ByteWraith1 · poc
https://github.com/ByteWraith1/CVE-2026-0073
nomisec FAILED
by novaek · poc
https://github.com/novaek/CVE-2026-0073-Research

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0001
EPSS Percentile 1.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-303
Status published
Products (7)
google/android 14.0
google/android 15.0
google/android 16.0 (4 CPE variants)
Google/Android 14
Google/Android 15
Google/Android 16
Google/Android 16-qpr2
Published May 04, 2026
Tracked Since May 05, 2026