---
title: "Mobile MCP Unvalidated URL Android Intent Injection - CVE-2026-35394"
description: "CVE-2026-35394: Mobile MCP intent injection before v0.0.50 passes any URI scheme to Android intents, enabling tel: USSD codes, calls, and SMS."
url: "https://anomity.ai/blog/mobile-mcp-intent-injection-cve-2026-35394/"
source: html
---

On this page

- What happened
- Why this is an agentic-endpoint risk
- How Anomity surfaces and governs it
- What to check across your fleet
- Frequently asked questions

[← Back to blog](https://anomity.ai/blog/)

- Home

- Blog

- Mobile MCP Unvalidated URL Android Intent Injection - CVE-2026-35394

![Anomity robot illustrating Mobile MCP Unvalidated URL Android Intent Injection - CVE-2026-35394]

Advisory High

# Mobile MCP Unvalidated URL Android Intent Injection - CVE-2026-35394

Anomity Research
Anomity Threat Research
·
May 19, 2026
·
4 min read

Share: Copied

MCP Server Security · High · CVE-2026-35394 · May 19, 2026

Affected Mobilenexthq Mobile MCP prior to v0.0.50

An MCP server with no URL scheme validation can place phone calls, send SMS, and dial USSD codes on a connected Android device - and most security stacks would never see the server, let alone the tool call. That is **Mobile MCP intent injection**, tracked as **CVE-2026-35394**, an intent injection flaw in Mobilenexthq Mobile MCP prior to **v0.0.50**. This advisory covers what the flaw allows, why it is an agentic-endpoint risk, and how [Anomity surfaces and governs MCP tool calls at the agent hook](https://anomity.ai/#runtime-governance).

## What happened

**CVE-2026-35394** is an intent injection vulnerability in **Mobile MCP** from Mobilenexthq, an MCP server that lets an AI agent drive a mobile device. In versions **before v0.0.50**, the `mobile_open_url` tool passes user-supplied URLs directly to Android's intent system with no scheme validation. Because any URI scheme is accepted, an attacker can trigger sensitive intents far beyond opening a web page - including USSD codes, phone calls, SMS messages, and content provider access.

A representative payload uses a `tel:` URI carrying a call-forwarding USSD string, delivered through the Mobile MCP server interface, which the device dialer then executes. The impact ranges from unauthorized calls and SMS to USSD-based account manipulation and reading sensitive content providers on the device. The fix in **v0.0.50** enforces proper URI scheme validation so only safe schemes reach the intent system. This is the same class of unreviewed, high-capability MCP wiring covered in the [MCP Server Security guide](https://anomity.ai/blog/mcp-server-security-complete-guide/).

## Why this is an agentic-endpoint risk

Mobile MCP is an AI artifact: an MCP server installed next to an agent so the agent can act on a device. It is one of the [eight AI artifact types](https://anomity.ai/#features) that live on managed endpoints and that traditional controls were never built to inventory. The flaw is not a classic network exploit - it is the agent invoking a tool exactly as designed, with input that was never constrained. That is what makes intent injection an endpoint problem rather than a perimeter one.

CVE-2026-35394 also widens the MCP attack surface in a direction defenders have not had to model. Earlier MCP cases concentrated on servers and shells - for example the standard-I/O execution surface covered in [Anthropic MCP stdio RCE by design](https://anomity.ai/blog/anthropic-mcp-stdio-by-design-rce/) and the unauthenticated transport in [MCPJam Inspector Remote Code Execution - CVE-2026-23744](https://anomity.ai/blog/mcpjam-inspector-rce-cve-2026-23744/). This flaw pushes the surface into device-level actions: a single unvalidated tool argument reaches the Android intent system and the telephony stack behind it. The wiring that grants that capability lives in a config no perimeter tool reads, which is exactly the blind spot [Anomity covers alongside your stack](https://anomity.ai/#compare).

## How Anomity surfaces and governs it

Anomity inventories the MCP servers wired into agents on every managed endpoint and treats Mobile MCP as a first-class artifact. It captures the configuration metadata, surfaces the exact version in use, and classifies the server - so finding every Mobile MCP instance prior to v0.0.50 is one query against your [fleet inventory](https://anomity.ai/#features) rather than a manual hunt across laptops.

Inventory tells you where the risk is; the hook is where it stops. On agents that expose a hook (for example, the `PreToolUse` event in Claude Code), Anomity evaluates each tool call against your policy and returns **allow**, **deny**, or **log** before the call runs. A `mobile_open_url` call carrying a `tel:`, `sms:`, or other non-web scheme can be denied even on an unpatched server, which gives you [runtime governance](https://anomity.ai/#runtime-governance) while the upgrade to v0.0.50 rolls out. Anomity collects metadata only, with on-endpoint secret redaction, so a tool argument is evaluated without shipping its contents off the device.

Every added, changed, or removed server, and every allow or deny decision, is recorded in a [queryable 90-day audit trail](https://anomity.ai/#outcomes) you can route to SIEM, Slack, email, or Jira. That gives you proof of which endpoints ran a vulnerable Mobile MCP, when it was upgraded, and which intent-bearing tool calls were blocked in the interim.

## What to check across your fleet

- Inventory every endpoint for Mobilenexthq Mobile MCP and record its version; upgrade anything prior to v0.0.50 .
- Where upgrading is not immediate, front the tool with a proxy that restricts URLs to http and https , or disable mobile_open_url entirely until patched.
- Add a policy at the agent hook that denies mobile_open_url calls carrying non-web schemes such as tel: , sms: , or content provider URIs.
- Identify which agents can drive a connected or emulated Android device through Mobile MCP, and scope that capability to who actually needs it.
- Review the audit trail for recent mobile_open_url calls and for Mobile MCP installs or version changes triggered outside normal workflows.

This advisory is part of our [MCP Server Security guide](https://anomity.ai/blog/mcp-server-security-complete-guide/). To see which endpoints run a vulnerable Mobile MCP and govern the tool calls before they reach the device, [book a 30-minute demo](https://anomity.ai/#early-access).

Share: Copied

## Frequently asked questions

Am I affected by CVE-2026-35394?
You are exposed if any managed endpoint runs Mobilenexthq Mobile MCP at a version prior to v0.0.50 and that server can drive a connected or emulated Android device. The `mobile_open_url` tool accepts any URI scheme with no validation, so an attacker who can influence the agent's input can reach the Android intent system. Upgrading to v0.0.50 enforces scheme validation. The harder problem is knowing which endpoints run the server in the first place, which requires a fleet inventory of the MCP servers wired into your agents.

What can an attacker do with the unvalidated URL?
Because the `mobile_open_url` tool forwards user-supplied URLs straight to Android's intent system without scheme validation, an attacker can supply non-web schemes such as `tel:`, `sms:`, or content provider URIs. A representative payload is a `tel:` URI carrying a call-forwarding USSD string, which the dialer executes. The impact ranges from placing unauthorized calls and sending SMS messages to USSD-based account manipulation and reading sensitive content providers on the device, all triggered through the Mobile MCP server interface rather than direct device access.

How do I remediate CVE-2026-35394 if I cannot upgrade immediately?
The fix in v0.0.50 enforces URI scheme validation so only safe schemes reach the intent system, and upgrading is the durable answer. Where you cannot upgrade right away, front the tool with a proxy that restricts URLs to `http` and `https`, or disable the `mobile_open_url` tool entirely until the server is patched. Both are stopgaps. Pair either one with a policy at the agent hook that denies the specific tool call, so an unpatched server still cannot reach the intent system through the agent on your endpoints.

How does Anomity help with Mobile MCP intent injection?
Anomity inventories the MCP servers wired into agents on every managed endpoint, surfaces the version in use, and flags Mobile MCP instances prior to v0.0.50 so finding every vulnerable copy is one query. On agents that expose a hook, it evaluates each tool call before it runs and returns allow, deny, or log, so a `mobile_open_url` call carrying a non-web scheme can be denied even on an unpatched server. Every install, version change, and decision lands in a queryable 90-day audit trail you can route to SIEM, Slack, email, or Jira.

## Related

[Advisory Critical ### mcp-atlassian HTTP Auth Bypass Falls Back to Global Credentials - CVE-2026-77254 CVE-2026-77254 (CVSS 9.1): unauthenticated HTTP MCP requests to mcp-atlassian below 0.22.0 fall through to globally configured Jira/Confluence credentials. Sibling CVE-2026-77244 (CVSS 10.0) accepts any non-empty token. Anomity Research · Sep 28, 2026 · CVE-2026-77254 (CVSS 9.1, GHSA-vc8m-84rp-53hx); sibling CVE-2026-77244 (CVSS 10.0, GHSA-wrhw-j3f9-8vc6)](https://anomity.ai/blog/mcp-atlassian-http-auth-bypass-global-credentials-cve-2026-77254/)

[Advisory Critical ### GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost CVE-2026-61568 (CVSS 9.6): @zereight/mcp-gitlab Streamable HTTP skipped SDK DNS-rebinding Host/Origin allowlists on loopback - fixed in 2.1.30. Anomity Research · Sep 21, 2026 · CVE-2026-61568 (CVSS 9.6, GHSA-vmp7-252j-cwp7)](https://anomity.ai/blog/mcp-gitlab-streamable-http-dns-rebinding-cve-2026-61568/)

[Advisory Critical ### MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding CVE-2026-59971 (CVSS 10.0): mysql-mcp-server SSE mode skipped Host/Origin DNS-rebinding protection, bound 0.0.0.0 with no auth - unauthenticated SQL until 0.4.2. Anomity Research · Sep 21, 2026 · CVE-2026-59971 (CVSS 10.0, GHSA-rqfv-2mw9-78g2)](https://anomity.ai/blog/mysql-mcp-server-sse-dns-rebinding-unauth-sql-cve-2026-59971/)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Mobile MCP Unvalidated URL Android Intent Injection - CVE-2026-35394",
  "description": "CVE-2026-35394: Mobile MCP intent injection before v0.0.50 passes any URI scheme to Android intents, enabling tel: USSD codes, calls, and SMS.",
  "datePublished": "2026-05-19",
  "dateModified": "2026-05-19",
  "author": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ]
  },
  "publisher": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ],
    "logo": {
      "@type": "ImageObject",
      "url": "https://anomity.ai/icon-512.png"
    }
  },
  "mainEntityOfPage": {
    "@type": "WebPage",
    "@id": "https://anomity.ai/blog/mobile-mcp-intent-injection-cve-2026-35394/"
  },
  "image": {
    "@type": "ImageObject",
    "url": "https://anomity.ai/assets/blog/covers/prompt-injection.jpg",
    "width": 1200,
    "height": 630
  },
  "articleSection": "MCP Server Security",
  "url": "https://anomity.ai/blog/mobile-mcp-intent-injection-cve-2026-35394/",
  "keywords": "Mobile MCP intent injection, CVE-2026-35394, MCP, intent injection, Android, agentic AI security, AI governance"
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Am I affected by CVE-2026-35394?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "You are exposed if any managed endpoint runs Mobilenexthq Mobile MCP at a version prior to v0.0.50 and that server can drive a connected or emulated Android device. The `mobile_open_url` tool accepts any URI scheme with no validation, so an attacker who can influence the agent's input can reach the Android intent system. Upgrading to v0.0.50 enforces scheme validation. The harder problem is knowing which endpoints run the server in the first place, which requires a fleet inventory of the MCP servers wired into your agents."
      }
    },
    {
      "@type": "Question",
      "name": "What can an attacker do with the unvalidated URL?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Because the `mobile_open_url` tool forwards user-supplied URLs straight to Android's intent system without scheme validation, an attacker can supply non-web schemes such as `tel:`, `sms:`, or content provider URIs. A representative payload is a `tel:` URI carrying a call-forwarding USSD string, which the dialer executes. The impact ranges from placing unauthorized calls and sending SMS messages to USSD-based account manipulation and reading sensitive content providers on the device, all triggered through the Mobile MCP server interface rather than direct device access."
      }
    },
    {
      "@type": "Question",
      "name": "How do I remediate CVE-2026-35394 if I cannot upgrade immediately?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The fix in v0.0.50 enforces URI scheme validation so only safe schemes reach the intent system, and upgrading is the durable answer. Where you cannot upgrade right away, front the tool with a proxy that restricts URLs to `http` and `https`, or disable the `mobile_open_url` tool entirely until the server is patched. Both are stopgaps. Pair either one with a policy at the agent hook that denies the specific tool call, so an unpatched server still cannot reach the intent system through the agent on your endpoints."
      }
    },
    {
      "@type": "Question",
      "name": "How does Anomity help with Mobile MCP intent injection?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Anomity inventories the MCP servers wired into agents on every managed endpoint, surfaces the version in use, and flags Mobile MCP instances prior to v0.0.50 so finding every vulnerable copy is one query. On agents that expose a hook, it evaluates each tool call before it runs and returns allow, deny, or log, so a `mobile_open_url` call carrying a non-web scheme can be denied even on an unpatched server. Every install, version change, and decision lands in a queryable 90-day audit trail you can route to SIEM, Slack, email, or Jira."
      }
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://anomity.ai/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Blog",
      "item": "https://anomity.ai/blog/"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "Mobile MCP Unvalidated URL Android Intent Injection - CVE-2026-35394",
      "item": "https://anomity.ai/blog/mobile-mcp-intent-injection-cve-2026-35394/"
    }
  ]
}
```
