Skip to finding
§
High
Wi-Fi — Android
Confirmed
CVE-2026-28662

A nearby Wi-Fi Direct peer can execute code in Android's Wi-Fi service without user interaction.

An oversized PBMA cookie length drives a heap write beyond the allocation in P2P2 bootstrap processing.

Affects

Android smartphones and other Android devices using the platform wpa_supplicant Wi-Fi Direct implementation.

What it enables

Adjacent remote code execution in the Android Wi-Fi service

Enter Wi-Fi radio range of an affected Android device.→↓Answer its P2P2 bootstrap Provision Discovery Request with an oversized cookie length in the PBMA attribute.→↓wpa_supplicant copies beyond its heap buffer.→↓The Android bulletin classifies the resulting capability as proximal remote code execution without user interaction.
Why this matters

This crosses directly from an unauthenticated radio peer into Android's Wi-Fi service without asking the user to approve a connection or take another action.

Detail and 2 sources
Required access

Wi-Fi radio range and the ability to answer a P2P2 bootstrap Provision Discovery Request from the target

Affected versions

Android 16, Android 16 QPR2, Android 17

The attacker enters Wi-Fi range, answers the target's P2P2 bootstrap Provision Discovery Request with an oversized cookie length, and causes wpa_supplicant to copy beyond its heap buffer.

The AOSP change and Android bulletin connect that attacker-controlled write to proximal remote code execution requiring no privileges or interaction.

The published fix closes this oversized-cookie path.

Evidence
The AOSP commit identifies a malicious Wi-Fi Direct peer, the oversized attacker-controlled cookie length, and the heap overflow.Google's Android bulletin and CVE classification identify CVE-2026-28662 as remote code execution requiring neither extra privileges nor user interaction.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 13, 2026