The History of Wireless ADB (Legacy Port 5555)
Historically, running ADB over Wi-Fi required connecting the device via USB first and executing `adb tcpip 5555`. While convenient, this had a major security vulnerability: any device on the same local Wi-Fi network could connect to port 5555 without authentication, potentially exposing device data and shell execution to malicious actors on open Wi-Fi.
Android 11+ Secure Wireless Debugging Architecture
Starting in Android 11 (API 30), Google introduced a completely revamped wireless debugging architecture using TLS 1.3 encryption and standard mDNS (Multicast DNS) zero-configuration discovery:
1. **Dynamic Pairing Port**: The device generates a temporary TCP port and a random 6-digit PIN code.
2. **PAKE (Password-Authenticated Key Exchange)**: When you run `adb pair <IP>:<PORT> <PIN>`, the client and device establish an encrypted TLS channel and exchange persistent RSA certificates.
3. **Dynamic Connection Port**: Once paired, the device opens an authenticated TLS socket on a secondary port for all subsequent ADB command traffic.
Step-by-Step Wireless Pairing Workflow
1. Connect your phone and PC to the same Wi-Fi network.
2. Open **Settings > Developer Options > Wireless Debugging** and toggle it ON.
3. Tap **"Pair device with pairing code"**.
4. Execute in terminal: `adb pair 192.168.1.150:38475 123456`
5. Once confirmed with `Successfully paired`, execute: `adb connect 192.168.1.150:41293`
6. Verify connection status with `adb devices -l`.