WRITEUP · PLATFORM · ADBD · 2026 · @YNSMROZTAS

Wireless debugging, trusted too soon

● live clk --:--:-- CVE-2026-0073

Platform class, not an app bug. AndroScope reports the debug surface. This page does not open a shell.

adbd // liveobserve
radar--:--:--
AndroScope adbd wireless debug no kit
01 Problem

Wireless debugging left on a LAN. adbd can accept a peer as trusted when it should not.

02 Move

Read posture only: toggle state, listen port class, patch level, pairing record present or not.

03 Evidence

Public class CVE-2026-0073. Same-LAN, no tap after the feature is already on.

04 Outcome

Patch ≥ 2026-05-01. Turn the feature off. Do not treat cafe Wi-Fi as a lab.

Summary

Wireless debugging is ADB over the local network with a pairing ceremony. The 2026 class is an authentication miss in adbd: a peer on the same LAN can be treated as already trusted. Impact class is a shell user on the device. No extra tap once the feature is enabled.

This is device posture, not com.vulnapp. AndroScope still cares — a lab build sitting on a shared SSID with wireless debugging on is a contaminated session.

Class: adbd wireless-debug trust. Source note: Mobile Hacker, May 2026. No connect command, no pairing walkthrough, no payload on this page.

Lab frame

Observer output only. Addresses and pairing material stripped.

Redacted debug-surface observer
Defense deck — debug surface armed, shell not opened

What has to be true

That is the whole precondition set this page will print. How the daemon is talked to stays off-site.

Why AndroScope logs it

PREPARE maps the app. RUNTIME still inherits the device. An open wireless-debug surface means findings from that session can be blamed on the wrong layer. The observer answers three questions and stops:

[debug] wireless debugging: ON
[debug] adbd on the local network
[debug] prior pairing record present
[debug] patch level older than 2026-05-01

no connect · no shell
mitsec@lab.device:

Fix

Credit

Public write-up of the class: Mobile Hacker — Android RCE via Wireless Debugging (May 2026). This page is a posture note in the mitsec voice, not a reprint and not an exploit guide.

YUNUS EMRE ÖZTAŞ · MITSEC · PLATFORM CLASS · NO KIT