Description
In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in WifiNetworkSuggestionsManager.java of Android, enabling persistent denial of service by exploiting a resource exhaustion flaw. An attacker can trigger unlimited consumption of system resources, leading to service slowdown or crash. The issue requires no elevated privileges and does not need user interaction.

Affected Systems

Android devices, specifically the Google Android platform. Precise affected versions are not disclosed in the CVE data; the vulnerability pertains to the WifiNetworkSuggestionsManager component.

Risk and Exploitability

The vulnerability is local and can be triggered by code running on the device with the same privilege level as the WifiNetworkSuggestionsManager component. The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low but non‑zero exploitation probability. It is not listed in the CISA KEV catalog no elevated privileges are required and user interaction is not needed, the primary risk is a local denial of service manifested as a slowdown or crash of the wifi suggestion service, potentially impacting overall device performance.

Generated by OpenCVE AI on September 10, 2026 at 23:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install the latest Android security patch that addresses CVE-2026-28617.
  • If Wi‑Fi network suggestions are not required, disable or uninstall the WifiNetworkSuggestionsManager component to eliminate the resource‑exhaustion vector.
  • Monitor device logs and performance metrics for signs of excessive resource consumption, particularly when Wi‑Fi network suggestions are active.

Generated by OpenCVE AI on September 10, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Sat, 12 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Fri, 11 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Persistent local denial of service via resource exhaustion in WifiNetworkSuggestionsManager

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Android Wi‑Fi Suggestions Resource Exhaustion Denial of Service
Weaknesses CWE-770

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Android Wi‑Fi Suggestions Resource Exhaustion Denial of Service
Weaknesses CWE-400
CWE-770

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T17:10:03.481Z

Reserved: 2026-03-02T19:11:09.009Z

Link: CVE-2026-28617

cve-icon Vulnrichment

Updated: 2026-09-10T17:09:56.900Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:53.853

Modified: 2026-09-15T14:23:43.973

Link: CVE-2026-28617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T06:45:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption