CVE-2026-59569
largeZscaler Client Connector Input Validation Flaw Allows Control Bypass on Android, ChromeOS
An improper input validation flaw (CWE-20) in Zscaler Client Connector on Android and ChromeOS allows an attacker to bypass Zscaler's security controls, such as web filtering and traffic inspection, on affected devices. Per the CVSS vector (AV:L/AC:L/PR:H/UI:N), exploitation is local: an attacker who already holds high privileges on the device supplies malformed input to the client to subvert its enforcement, with no user interaction required. Successful abuse would let a user or process route traffic outside Zscaler's protective tunnel, undermining web filtering, DLP, and zero-trust policies applied to the device. Organizations deploying Client Connector to managed or BYOD Android and ChromeOS devices are the affected population. No public proof of concept exists, the issue is not on CISA's KEV list, and no exploitation in the wild has been reported.
What to do: Upgrade Zscaler Client Connector to the latest available release on all Android and ChromeOS devices and consult Zscaler's security advisory for the specific patched build. Because exploitation requires an attacker to already hold high privileges on the device, use MDM to restrict admin/root access, sideloading, and app tampering on managed endpoints. Watch the Zscaler admin console and device posture logs for out-of-date Client Connector versions or devices whose traffic is bypassing the Zscaler tunnel.
| Zscaler Client Connector for Android | — |
| Zscaler Client Connector for ChromeOS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.