Microsoft Patches Critical UFO Vulnerability Affecting Android Device Control
A vulnerability in Microsoft's UFO framework, CVE-2026-73296, permits remote control of Android devices and is rated 9.4 on the CVSS scale. Organizations utilizing UFO versions prior to 3.0.8 must upgrade immediately to mitigate risks associated with misconfigured Mobile Model Context Protocol services.

Microsoft has released version 3.0.8 of its UFO automation framework to address CVE-2026-73296, a critical vulnerability affecting Android devices. The flaw allows unauthenticated attackers to exploit exposed Mobile Model Context Protocol services, enabling full remote control without user interaction.
The vulnerability primarily affects systems where these services are not bound to localhost, thereby exposing them to network access. Organizations should restrict access to TCP ports 8020 and 8021, utilize TLS, and review connected devices to prevent potential exploitation. The risk of data breaches and unauthorized access to credentials necessitates immediate action to secure UFO deployments.




Comments