Executive brief
Zscaler Client Connector is a security client used to protect mobile and chromebook devices by securely routing traffic through Zscaler's cloud security platform. A buffer overflow flaw in the application can be exploited by a local attacker to crash the application, disrupting the user's network security protection and potentially leaving the device vulnerable during the outage.
Technical details
A locally exploitable buffer overflow vulnerability exists in Zscaler Client Connector on Android and ChromeOS platforms. The vulnerability allows a local attacker with access to the affected device to trigger the buffer overflow through a malformed input, causing the application to crash and resulting in a denial-of-service condition. No network access or authentication is required for exploitation. The attack impacts availability by preventing the security client from operating, removing the device's connection to Zscaler's security services. Patches are expected to be available in updated releases of Client Connector.
Affected products
- Zscaler Client Connector <UNKNOWN>
Timeline
- 2026-08-24: disclosed