Executive brief
Zscaler Client Connector is a security application that protects mobile and chromebook devices by enforcing security policies and controls. An improper input validation flaw allows attackers to bypass these security controls, potentially exposing devices to unauthorized network access or policy circumvention.
Technical details
The vulnerability is an improper input validation issue in Zscaler Client Connector affecting Android and ChromeOS platforms. The flaw permits an attacker to craft malicious input that bypasses Zscaler's security controls. The attack vector appears to be network-based, though specific preconditions and the exact mechanism for exploitation are not detailed in the available advisory content. Successful exploitation would allow circumvention of intended security policies enforced by the connector.
Affected products
- Zscaler Client Connector <UNKNOWN>
Timeline
- 2026-09-14: disclosed