Manthan Ghasadiya@g_m_j_2703Disclosure
The post enumerates several new high‑CVSS vulnerabilities across various MCPs and notes additional MCP issues in popular platforms.
Manthan Ghasadiya@g_m_j_2703PoC
The author discloses CVE‑2026‑35394, presenting a prompt injection PoC that turns an AI assistant into a universal remote for Android, but provides no evidence of real‑world exploitation or mitigation.
Manthan Ghasadiya@g_m_j_2703PoC
The post announces a Proof of Concept for CVE‑2026‑35394 with technical depth and payloads provided via a Medium article, but it does not report active exploitation or a patch.
CVE@CVEnewDisclosure
The CVE-2026-35394 entry describes a flaw where Mobile Next’s mobile_open_url tool passes user‑supplied URLs directly to Android prior to version 0.0.50, potentially enabling exploitation, but no PoC, exploit, patch, or active use details are provided.
‘BBWriteups’@bbwriteupPoC
The post announces CVE-2026-35394 and links to a Medium article that presumably shares a Proof of Concept for exploiting Android devices via AI prompt injection, with no additional technical, patch, or active exploitation details provided.