Description
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.
Published: 2026-08-24
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A buffer overflow in the Zscaler Client Connector can be triggered by a user with local access and leads to a local denial of service on Android and ChromeOS devices. The overflow corrupts memory and causes the client process to crash, taking the user out of the security tunnel. The vulnerability belongs to CWE-229, a type of improper handling that results in resource exhaustion and interruption of services.

Affected Systems

The affected vendors are Zscaler, specifically the Client Connector application that runs on Android and ChromeOS operating systems.

Risk and Exploitability

The CVSS base score of 8.4 rates this vulnerability as high severity. Based on the description, it is inferred that local access (i.e., any user logged onto the device) may be sufficient to exploit this buffer overflow, allowing a local attacker to force the client process to crash. No public exploit is listed, and the vulnerability is not in the CISA KEV catalog. The high CVSS score and local nature of the vulnerability suggest that the risk remains significant for environments where the Client Connector is deployed on potentially untrusted or highly privileged devices.

Generated by OpenCVE AI on August 24, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Zscaler Client Connector update that addresses the buffer overflow.
  • If an immediate update cannot be deployed, uninstall or disable the Client Connector on critical devices to prevent the local crash.
  • Configure device security settings to isolate the Client Connector process from executing arbitrary memory and monitor for repeated crash events.

Generated by OpenCVE AI on August 24, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Zscaler
Zscaler client Connector
Vendors & Products Zscaler
Zscaler client Connector
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.
Title Local denial-of-service
Weaknesses CWE-229
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zscaler Client Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: Zscaler

Published:

Updated: 2026-08-24T15:17:49.354Z

Reserved: 2026-07-06T06:18:59.633Z

Link: CVE-2026-59566

cve-icon Vulnrichment

Updated: 2026-08-24T15:17:41.317Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T14:16:55.940

Modified: 2026-08-28T18:39:48.167

Link: CVE-2026-59566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:15:04Z

Weaknesses
  • CWE-229

    Improper Handling of Values