Skip to finding
important · Wi-Fi — Android

A nearby Wi-Fi peer can execute code in Android’s Wi-Fi component without user interaction.

Affects

Android phones and other Android devices using the platform wpa_supplicant Wi-Fi Direct implementation.

A crafted Wi-Fi Direct provisioning-discovery bootstrap request reaches p2p_process_prov_disc_bootstrap_req(), causes a heap out-of-bounds write and can execute code in the Wi-Fi component.

Detail and 2 sources

Google published per-branch fixes and affected ranges. We do not know whether old images remain accepted, revocation is complete or end-of-life devices are covered.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 9, 2026