Impact
A buffer overflow in the Zscaler Client Connector can be triggered by a user with local access and leads to a local denial of service on Android and ChromeOS devices. The overflow corrupts memory and causes the client process to crash, taking the user out of the security tunnel. The vulnerability belongs to CWE-229, a type of improper handling that results in resource exhaustion and interruption of services.
Affected Systems
The affected vendors are Zscaler, specifically the Client Connector application that runs on Android and ChromeOS operating systems.
Risk and Exploitability
The CVSS base score of 8.4 rates this vulnerability as high severity. Based on the description, it is inferred that local access (i.e., any user logged onto the device) may be sufficient to exploit this buffer overflow, allowing a local attacker to force the client process to crash. No public exploit is listed, and the vulnerability is not in the CISA KEV catalog. The high CVSS score and local nature of the vulnerability suggest that the risk remains significant for environments where the Client Connector is deployed on potentially untrusted or highly privileged devices.
OpenCVE Enrichment