¡¾·ì϶¹«¸æ¡¿Android ADB ÈÏÖ¤ÈÆ¹ý·ì϶(CVE-2026-0073)
°ä²¼¹¦·ò 2026-05-06Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Android ADB ÈÏÖ¤ÈÆ¹ý·ì϶ | ||
CVE ID | CVE-2026-0073 | ||
·ì϶ÀàÐÍ | ÈÏÖ¤ÈÆ¹ý | ·¢ÏÖ¹¦·ò | 2026-5-6 |
·ì϶ÆÀ·Ö | 8.8 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ¾ÖÓòÍø | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
AndroidÊÇGoogleÍÆ³öµÄÒÆ¶¯²Ù×÷ϵͳ£¬¿í·ºÀûÓÃÓÚÖÇÄÜÊÖ»ú¡¢Æ½°å¼°Ç¶ÈëʽÉ豸£¬Ìṩ¸øÓ÷¨Ê½ÖÎÀí¡¢Ó²¼þÇý¶¯¡¢ÏµÍ³°²È«ºÍÍøÂçͨѶְÄÜ£¬Ö§³Öwireless ADBµ÷ÊÔ¼°Ô¶³ÌÖÎÀí¡£
2026Äê5ÔÂ6ÈÕ£¬±¦ÔËÀ³¹Ù·½ÍøÕ¾°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Android ADBÈÏÖ¤ÈÆ¹ý·ì϶¡£¸Ã·ì϶´æÔÚÓÚplatform/packages/modules/adb/daemon/auth.cppÎļþÖУ¬ÓÉÓÚadbd_tls_verify_certʹÓÃEVP_PKEY_cmpÑéÖ¤¿Í»§¶ËÖ¤Ê鹫ԿʱºöÂÔ¿çËã·¨±ÈÁ¦·µ»ØÖµ£¬µ¼Ö¹¥»÷Õß¿ÉÔÚÎÞÐèÓû§½»»¥Çé¿öÏÂÈÆ¹ýÉí·ÝÑéÖ¤£¬Í¨¹ýÌṩ·ÇRSA TLS¿Í»§¶ËÖ¤Êé³ÉΪÊÚȨADB host²¢»ñÈ¡shellÓû§È¨ÏÞ£¬´Ó¶øÔ¶³Ì½Ó¼ûϵͳµ÷ÊÔ½Ó¿Ú£¬¶ÁÈ¡Ãô¸ÐÐÅÏ¢¡¢Ö´ÐкÅÁî¡¢Åú¸ÄÅäÖ㬿ÉÄÜÎ¥·´Êý¾Ý±£»¤ºÍÆóÒµ°²È«Õþ²ß£¬¶Ô»ú¹¹ºÍÓû§°²È«Ôì³ÉÑϳÁÓ°Ïì¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://source.android.com/docs/security/bulletin/2026/2026-05-01?hl=zh-cn/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ