Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-35394: mobile-mcp URL tool allows arbitrary Android intent execution

The mobile_open_url tool in the mobile-mcp MCP server passed user-supplied URLs directly to Android's intent system without scheme validation, allowing execution of arbitrary intents such as USSD codes, phone calls, SMS messages and content provider access. The issue affects versions prior to 0.0.50 and is fixed in 0.0.50.

Disclosed 6 April 2026 · Record updated 13 September 2026

Impact

An attacker supplying a crafted URL could trigger arbitrary Android intents on the connected device, including dialling USSD codes, placing calls, sending SMS messages and accessing content providers.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-35394