| ▲ | gnfargbl 4 hours ago | ||||||||||||||||
You, and may of the people in the thread here are at cross purposes, I think. The CVE mentioned in the article is https://nvd.nist.gov/vuln/detail/CVE-2026-0073. That's a real CVE: logic error leading to auth bypass. Fix can be seen at https://android.googlesource.com/platform/packages/modules/a.... Separately, a number of people here are attempting to argue that the availability of On-Device ADB should be regarded as a "CVE" in and of itself. Google does not appear to share that view. | |||||||||||||||||
| ▲ | dns_snek 4 hours ago | parent [-] | ||||||||||||||||
> Separately, a number of people here are attempting to argue that the availability of On-Device ADB should be regarded as a "CVE" in and of itself. Google does not appear to share that view. This was proposed by a Google employee: https://issuetracker.google.com/issues/526109803#comment3 | |||||||||||||||||
| |||||||||||||||||