Impact
A flaw in Google’s Android 802.11 common module occurs in the function get_eht_operation_channel_width of ieee802_11_common.c, where an incorrect bounds check allows a buffer over‑read (CWE-120). This out‑of‑bounds read can expose data residing in the device’s memory, enabling an attacker to obtain sensitive information without requiring additional execution privileges or user interaction.
Affected Systems
The affected software is Google:Android’s 802.11 common module, part of Android’s wireless networking stack; no specific version or patch level is mentioned, and the vulnerability could affect any Android installation that includes the vulnerable module.
Risk and Exploitability
The CVSS score of 3.5 indicates a low severity level. The EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA KEV catalog. The likely attack vector requires proximity to the device and the ability to transmit specially crafted Wi‑Fi frames that trigger the read, but otherwise requires no additional user or system privileges.
OpenCVE Enrichment