Android Wireless Debugging Opens a New Shell Path

Android malware no longer needs a cable to cross from app-level compromise into shell-level control. A new RedHook variant abuses Wireless ADB, so the dangerous step is now tied to a built-in debugging feature that users may enable without thinking about the larger exposure. The report says the malware can use Android Wireless Debugging to obtain shell-level privileges without a computer connection. That expands the attack surface from USB-dependent access to any path that convinces a user to turn on wireless debugging on a compromised device. For teams managing employee or personal Android fleets, the weak point is no longer just app permissions or plugged-in debugging. Any control that assumes a missing USB cable blocks shell access is now too narrow.

Part of the PlainSec briefing for 2026-07-12

Sources