A nearby Wi-Fi Direct peer can execute code in Android's Wi-Fi service without user interaction.
An oversized PBMA cookie length drives a heap write beyond the allocation in P2P2 bootstrap processing.
Android smartphones and other Android devices using the platform wpa_supplicant Wi-Fi Direct implementation.
Adjacent remote code execution in the Android Wi-Fi service
This crosses directly from an unauthenticated radio peer into Android's Wi-Fi service without asking the user to approve a connection or take another action.
Detail and 2 sources
The attacker enters Wi-Fi range, answers the target's P2P2 bootstrap Provision Discovery Request with an oversized cookie length, and causes wpa_supplicant to copy beyond its heap buffer.
The AOSP change and Android bulletin connect that attacker-controlled write to proximal remote code execution requiring no privileges or interaction.
The published fix closes this oversized-cookie path.
- access:radio:wifi
- within Wi-Fi range
- interaction:none
- no user action required
- Revocation complete
- Yes
The revocation answer means the patch has no revocation dependency; it does not describe a separate revocation campaign.