← Back to context

Comment by 3form

12 hours ago

Because you know, the actual solution would be to have more granularity in authentication process than "allow whole device to attach to ADB", but that would be like, difficult... so they're not going to so that.

Right now any app on my PC connected to ADB could manipulate my phone then, and that's somehow not a CVE?

Is it a CVE that an app running on my PC could actually be running under GDB? It's the entire purpose of these tools.