Executive brief
wpa_supplicant is a wireless authentication client used in Android devices and other systems to connect to Wi-Fi networks securely. A flaw in input validation allows an attacker within Wi-Fi range to write data to unauthorized memory locations, potentially enabling device compromise, data theft, or service disruption.
Technical details
An improper input validation vulnerability in wpa_supplicant prior to the September 2026 SMR release allows adjacent attackers to write out-of-bounds memory. The vulnerability requires physical proximity (adjacent network access), as indicated by the attack vector. The attacker can exploit this flaw to overwrite memory regions beyond intended bounds, potentially leading to code execution, privilege escalation, or denial of service depending on what memory is overwritten. Patches are available in the Samsung Mobile Security Update for September 2026 and later.
Affected products
- Linux wpa_supplicant prior to September 2026 release
- Samsung Android versions with wpa_supplicant prior to SMR Sep-2026 Release 1
Timeline
- 2026-09-09: disclosed
- 2026-09: patched: Samsung Mobile Security Update (SMR Sep-2026 Release 1) contains patches