Microsoft UFO MCP Flaw Exposes Android Devices to Remote Control Attacks
A critical vulnerability in Microsoft's open-source UFO Desktop AgentOS has been discovered, allowing remote attackers to access and control Android devices connected via the platform's Mobile Model Context Protocol (MCP) servers without requiring authentication.
The issue is linked to UFO's Mobile MCP data-collection and action servers, which expose Android Debug Bridge (ADB)-based functionality over Streamable HTTP. When operators follow the project's documented remote-deployment configuration and bind the services to 0.0.0.0, they become accessible on TCP ports 8020 and 8021 to any network client that can reach them.
Attackers could potentially access sensitive material visible on a connected device, including messages, one-time passwords, credentials, personal data, and application content.