Description
In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-10-05
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution with System privileges
Action: Assess Impact
AI Analysis

Impact

An out‑of‑bounds write was discovered in the wpas_handle_robust_av_scs_recv_action function of Android’s wpa_supplicant implementation. The logic error permits an attacker to corrupt boundary checks, enabling execution of arbitrary code with system privileges. This flaw can compromise confidentiality, integrity, and availability of the device and is identified by CWE‑119 and CWE‑787.

Affected Systems

The flaw affects the Google Android platform, specifically the wpa_supplicant component used for wireless authentication. No specific version range is listed, so all current Android releases that contain the vulnerable code path may be impacted until a vendor fix is released.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity risk, and the EPSS score is not available. Based on the description, the likely attack vector is exploitation via crafted Wi‑Fi traffic that triggers the vulnerable parsing routine; no user interaction is needed. The vulnerability is listed in the CISA KEV catalog as not listed, so public exploits are not known yet, but the combination of a boundary overrun and elevated privilege grants an attacker near‑complete control over the affected device. In the absence of a patch, this represents a critical security gap that could be abused by network‑based adversaries.

Generated by OpenCVE AI on October 5, 2026 at 22:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the Android security bulletin for a patch and upgrade the device to the latest available firmware as soon as the fix is released.
  • If a patch is not yet available, disable Wi‑Fi or block all traffic to the wpa_supplicant service to reduce exposure.
  • Consider implementing network segmentation or firewall rules to isolate the device from untrusted networks until the vulnerability is remediated.
  • Enable VPN or restrict Wi‑Fi to known, trusted networks to limit potential attacker access during the interim period.

Generated by OpenCVE AI on October 5, 2026 at 22:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Android WPA Supplicant Allows Remote Code Execution
Weaknesses CWE-119

Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Android WPA Supplicant Allows Remote Code Execution
Weaknesses CWE-119
CWE-787

Mon, 05 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Mon, 05 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
Description In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-10-05T19:42:14.292Z

Reserved: 2026-06-02T14:29:35.575Z

Link: CVE-2026-49878

cve-icon Vulnrichment

Updated: 2026-10-05T19:41:58.147Z

cve-icon NVD

Status : Received

Published: 2026-10-05T19:17:20.650

Modified: 2026-10-05T20:17:21.407

Link: CVE-2026-49878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T22:30:19Z

Weaknesses