ZeroHour

CVE-2026-59569

large

Zscaler Client Connector Input Validation Flaw Allows Control Bypass on Android, ChromeOS

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

An improper input validation flaw (CWE-20) in Zscaler Client Connector on Android and ChromeOS allows an attacker to bypass Zscaler's security controls, such as web filtering and traffic inspection, on affected devices. Per the CVSS vector (AV:L/AC:L/PR:H/UI:N), exploitation is local: an attacker who already holds high privileges on the device supplies malformed input to the client to subvert its enforcement, with no user interaction required. Successful abuse would let a user or process route traffic outside Zscaler's protective tunnel, undermining web filtering, DLP, and zero-trust policies applied to the device. Organizations deploying Client Connector to managed or BYOD Android and ChromeOS devices are the affected population. No public proof of concept exists, the issue is not on CISA's KEV list, and no exploitation in the wild has been reported.

What to do: Upgrade Zscaler Client Connector to the latest available release on all Android and ChromeOS devices and consult Zscaler's security advisory for the specific patched build. Because exploitation requires an attacker to already hold high privileges on the device, use MDM to restrict admin/root access, sideloading, and app tampering on managed endpoints. Watch the Zscaler admin console and device posture logs for out-of-date Client Connector versions or devices whose traffic is bypassing the Zscaler tunnel.

Affected
Zscaler Client Connector for Android
Zscaler Client Connector for ChromeOS
Estimated exposure
large≈ hundreds of thousands to ~1M Android/ChromeOS devices (estimated subset of Zscaler's ~45M-user base) — Zscaler reports a platform user base in the tens of millions across thousands of enterprise customers, and Android is a common managed/BYOD client platform, so the mobile Client Connector install base is plausibly in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.