• Sources: Google issue 526109803, CVE-2026-0073 (NVD), write-up, HN 49045159
  • Summary: A feature request on Google's issue tracker asks for control over which network interface the ADB daemon listens on. The request follows CVE-2026-0073, a logic error in adbd_tls_verify_cert in auth.cpp that bypasses wireless ADB mutual authentication and allows proximal remote code execution as the shell user with no user interaction. In the thread an ADB maintainer suggests binding only to the Wi-Fi interface, which would drop loopback connections and so break on-device ADB clients that connect to 127.0.0.1, including Shizuku, libadb-android, and ADB use from terminal emulators such as Termux. A write-up published 2026-07-20 and last edited 2026-07-24 walks through the thread and states that this is not a Google announcement and that no implementation exists. Debugging from a connected host over USB is outside the proposal.
  • Why it matters: A large class of Android tooling that grants elevated capability without root depends on an on-device ADB connection over loopback, and closing that interface to fix a wireless authentication bug would remove it.
  • Follow-up: Watch for a Google decision on the request, whether any AOSP change lands, and whether an interface allowlist preserves loopback.

send feedback on this story