¡¾·ì϶¹«¸æ¡¿Android ADB ÈÏÖ¤ÈÆ¹ý·ì϶(CVE-2026-0073)
°ä²¼¹¦·ò 2026-05-06Ò»¡¢¡¢¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | Android ADB ÈÏÖ¤ÈÆ¹ý·ì϶ | ||
CVE ID | CVE-2026-0073 | ||
·ì϶ÀàÐÍ | ÈÏÖ¤ÈÆ¹ý | ·¢ÏÖ¹¦·ò | 2026-5-6 |
·ì϶ÆÀ·Ö | 8.8 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ¾ÖÓòÍø | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
AndroidÊÇGoogleÍÆ³öµÄÒÆ¶¯²Ù×÷ϵͳ£¬£¬£¬¿í·ºÀûÓÃÓÚÖÇÄÜÊÖ»ú¡¢¡¢¡¢Æ½°å¼°Ç¶ÈëʽÉ豸£¬£¬£¬Ìṩ¸øÓ÷¨Ê½ÖÎÀí¡¢¡¢¡¢Ó²¼þÇý¶¯¡¢¡¢¡¢ÏµÍ³°²È«ºÍÍøÂçͨѶְÄÜ£¬£¬£¬Ö§³Öwireless ADBµ÷ÊÔ¼°Ô¶³ÌÖÎÀí¡£¡£
2026Äê5ÔÂ6ÈÕ£¬£¬£¬OG¶«·½Ìü°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Android ADBÈÏÖ¤ÈÆ¹ý·ì϶¡£¡£¸Ã·ì϶´æÔÚÓÚplatform/packages/modules/adb/daemon/auth.cppÎļþÖУ¬£¬£¬ÓÉÓÚadbd_tls_verify_certʹÓÃEVP_PKEY_cmpÑéÖ¤¿Í»§¶ËÖ¤Ê鹫ԿʱºöÂÔ¿çËã·¨±ÈÁ¦·µ»ØÖµ£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÔÚÎÞÐèÓû§½»»¥Çé¿öÏÂÈÆ¹ýÉí·ÝÑéÖ¤£¬£¬£¬Í¨¹ýÌṩ·ÇRSA TLS¿Í»§¶ËÖ¤Êé³ÉΪÊÚȨADB host²¢»ñÈ¡shellÓû§È¨ÏÞ£¬£¬£¬´Ó¶øÔ¶³Ì½Ó¼ûϵͳµ÷ÊÔ½Ó¿Ú£¬£¬£¬¶ÁÈ¡Ãô¸ÐÐÅÏ¢¡¢¡¢¡¢Ö´ÐкÅÁî¡¢¡¢¡¢Åú¸ÄÅäÖ㬣¬£¬¿ÉÄÜÎ¥·´Êý¾Ý±£»£»¤ºÍÆóÒµ°²È«Õþ²ß£¬£¬£¬¶Ô»ú¹¹ºÍÓû§°²È«Ôì³ÉÑÏÖØÓ°Ïì¡£¡£
¶þ¡¢¡¢¡¢Ó°ÏìÁìÓò
Èý¡¢¡¢¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º£ºhttps://source.android.com/docs/security/bulletin/2026/2026-05-01?hl=zh-cn/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ