Impact
A flaw in Zscaler Client Connector on Android devices allows a pre‑installed peer application to terminate the Zscaler tunnel, force the user to log out, and toggle packet capture, resulting in an abrupt interruption of network connectivity classic improper input validation flaw, classified as CWE‑20.
Affected Systems
The vulnerability affects the Zscaler Client Connector application on Android. All installed instances of the client that include the pre‑installed peer app are impacted; specific version details were not disclosed.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity. The EPSS score of 0.00094, a very low exploitation probability, indicates that the likelihood of exploitation is minimal, but not zero, and the lack of KEV listing suggests no documented active exploitation yet. The attack vector is presumed to be local or through installation of the peer app, as no network‑based vectors are described.
OpenCVE Enrichment