Impact
Zscaler Client Connector on Android and ChromeOS contains an improper input validation flaw (CWE-20) that may allow an attacker to send crafted requests and bypass Zscaler controls. The flaw can enable unauthorized network access or elevate an attacker’s privileges relative to the VPN service, potentially undermining the security posture of the client’s network traffic.
Affected Systems
Zscaler Client Connector installations on Android and ChromeOS are affected. No specific version information is supplied, so all installed instances of the client on these operating systems should be considered vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% and absence from the CISA KEV catalog imply that the vulnerability has not yet been actively exploited in the wild. It is inferred that the attack vector relies on an attacker crafting malicious input to the client; this may be achieved via local or network interfaces that the client exposes, but the exact method of delivery is not explicitly detailed in the description.
OpenCVE Enrichment