Impact
An out‑of‑bounds write was discovered in the wpas_handle_robust_av_scs_recv_action function of Android’s wpa_supplicant implementation. The logic error permits an attacker to corrupt boundary checks, enabling execution of arbitrary code with system privileges. This flaw can compromise confidentiality, integrity, and availability of the device and is identified by CWE‑119 and CWE‑787.
Affected Systems
The flaw affects the Google Android platform, specifically the wpa_supplicant component used for wireless authentication. No specific version range is listed, so all current Android releases that contain the vulnerable code path may be impacted until a vendor fix is released.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity risk, and the EPSS score is not available. Based on the description, the likely attack vector is exploitation via crafted Wi‑Fi traffic that triggers the vulnerable parsing routine; no user interaction is needed. The vulnerability is listed in the CISA KEV catalog as not listed, so public exploits are not known yet, but the combination of a boundary overrun and elevated privilege grants an attacker near‑complete control over the affected device. In the absence of a patch, this represents a critical security gap that could be abused by network‑based adversaries.
OpenCVE Enrichment