Comment by dns_snek
12 hours ago
Can you provide a reasonable definition where an authentication bypass in ADB doesn't qualify as a vulnerability? Is there a use case for allowing anyone on your network to run adb commands without your approval?
There are 3 things which I feel like are being confused here:
1. There was a genuine authentication bypass vulnerability in ADB (bad)
2. Initial proposed change wants to add an option to limit the ADB server to certain IPs or network interfaces (good - it doesn't affect you)
3. Response to the original request, proposing that ADB shouldn't be allowed to listen on loopback interfaces (bad/nefarious - it breaks functionality)
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-0073
[2] https://issuetracker.google.com/issues/526109803#comment1
[3] https://issuetracker.google.com/issues/526109803#comment3
The act of "allowing“ negates the “without your approval“. You see the failure in the logic here I hope.
I thought we were having a technical discussion not a linguistic one. Baseline level of technical understanding is expected. s/allowing/enabling/.
allow [intransitive verb]: to make a possibility
https://www.merriam-webster.com/dictionary/allow