Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control… — Pentesting News — TG.ME

Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication

https://gbhackers.com/critical-microsoft-ufo-mcp-flaw/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication
A critical vulnerability in Microsoft’s open-source UFO Desktop AgentOS could allow remote attackers to access and control Android devices connected via the platform’s Mobile Model Context Protocol (MCP) servers without requiring authentication.
August 31, 2026 129 1