CVE-2026-59566

8.4

Zscaler · Client Connector

A buffer overflow vulnerability in Zscaler Client Connector for Android and ChromeOS allows a local attacker to trigger a denial of service condition.

Executive summary

A locally exploitable buffer overflow in Zscaler Client Connector for Android and ChromeOS poses a significant risk of service disruption.

Vulnerability

This vulnerability involves improper handling of values, manifesting as a buffer overflow. The attack vector is local, and it does not require authentication or user interaction to execute.

Business impact

Successful exploitation results in a local denial of service, which can render the Zscaler security agent unresponsive. Given the CVSS score of 8.4, the high severity reflects the potential for complete loss of security visibility and network connectivity on affected mobile and endpoint devices.

Remediation

Immediate Action: Update Zscaler Client Connector to version 4.2 or later on all managed Android and ChromeOS devices.

Proactive Monitoring: Review device logs for unexpected application crashes or service restarts that may indicate attempted exploitation.

Compensating Controls: Restrict physical or local access to corporate mobile devices to minimize the risk of unauthorized local interaction.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability necessitates prompt action to prevent service outages. Administrators should prioritize the deployment of the 4.2 update across the organization to ensure the continued integrity of endpoint security.

More Zscaler CVEs