Impact
Microsoft UFO’s type_text and launch_app tools allow an authenticated caller to inject shell metacharacters into the adb command that the Android device executes. The application concatenates the caller‑controlled text and package_name values directly into the adb shell command string without sanitization. As a result, an attacker who possesses a valid Mobile MCP API key and an ADB‑enabled device can execute arbitrary shell commands on the device as the Android shell user. The vulnerability does not provide host‑OS or root privileges, but it enables the attacker to run commands that may read, modify, or exfiltrate data on the device.
Affected Systems
The flaw exists in the Microsoft UFO framework for all releases older than v3.0.10. The affected component is the ufo/client/mcp/http_servers/mobile_mcp_server.py module that implements the Mobile MCP HTTP API. Users running any version prior to 3.0.10 that exposes the type_text or launch_app endpoints to authenticated callers are at risk. The vendor/product affected is Microsoft UFO, an open‑source automation framework that can be used on any platform that supports ADB‑enabled Android devices.
Risk and Exploitability
The CVSS score of 8.8 reflects a high‑severity exploitation that delivers command‑execution privileges. The EPSS score is not available, but the requirement for an authenticated Mobile MCP API key and a reachable, ADB‑authorised device limits the attacker to environments where credentials or device access have already been compromised. Because the exploit does not grant root or host‑OS access, the attack surface is bounded to the Android shell user. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed publicly‑exploited instances yet, but the high severity warrants immediate attention if the affected version is in use.
OpenCVE Enrichment