Skip to finding
important · Mobile Wi-Fi

Nearby Wi-Fi traffic can make Android read beyond its 802.11 parser buffer and disclose information.

Affects

Android phones, tablets, and other devices using Android's wpa_supplicant-derived Wi-Fi stack.

Malformed EHT-operation data reaches an incorrect bounds check without user interaction; Google has published a fix.

Detail and 2 sources

We do not know which frame role reaches the parser or how the transmitter observes the out-of-bounds bytes.

Chain to watch
Recover the AOSP fix and identify the caller that reaches the EHT parser.→↓Trace any response path that could expose out-of-bounds bytes to the transmitter.→↓The observable extraction path from the parser’s out-of-bounds read remains unestablished.
Unverified chainReproduce malformed EHT Operation elements while tracing parser callers and outbound responses.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 11, 2026