ZeroHour

CVE-2026-28662

mass

Heap Buffer Overflow in Android Wi-Fi Direct (P2P) Provisioning Discovery Enables Nearby RCE

CVSS 3.1
8.0 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-28662 is a heap buffer overflow causing an out-of-bounds write in p2p_process_prov_disc_bootstrap_req in p2p_pd.c, the code that handles Wi-Fi P2P (Wi-Fi Direct) provisioning discovery bootstrap requests in Android's Wi-Fi stack. It is triggered when a nearby attacker sends a crafted bootstrap request over the air while the device's Wi-Fi is enabled; no user interaction or privileges are required. Successful exploitation yields remote (proximal/adjacent) code execution, meaning anyone within Wi-Fi radio range could run code on the device. Android devices running software prior to the September 2026 Android Security Update are affected. Exploitation is not currently observed: there is no public proof-of-concept, it is not in CISA's KEV, and EPSS puts 30-day exploitation probability at about 0.1%.

What to do: Install the September 2026 Android Security Update (or your device vendor's equivalent build) as soon as it is available and verify the patch level in Settings > About phone. Until patched, consider disabling Wi-Fi Direct/peer-to-peer sharing and Wi-Fi when not needed, since exploitation requires proximity. The patch is part of the September 2026 release that fixes 180 vulnerabilities in total.

Affected
Google / Android (CNA: [email protected]) Android OS Wi-Fi P2P (Wi-Fi Direct) stack, p2p_process_prov_disc_bootstrap_req in p2p_pd.c
Estimated exposure
massorder of billions of Android devices worldwide carry the affected Wi-Fi Direct code, though exploitation requires an attacker within radio range — Android has billions of active devices and Wi-Fi Direct/P2P support is broadly enabled on modern builds, per public Android device-population figures, so the vulnerable code is plausibly present at mass scale even though remote reach is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendors
google
Products
android
Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Android’s September 2026 Updates Patch 180 Vulnerabilities

Google's September 2026 Android security updates patch 180 vulnerabilities including critical Wi-Fi memory corruption flaw CVE-2026-28662.

Google released September 2026 Android security updates addressing 180 vulnerabilities across two patch levels. The 2026-09-01 level fixes 95 bugs including 23 critical System component flaws enabling RCE, EoP, and DoS. The 2026-09-05 level addresses 85 additional defects in kernel and vendor components including a Wi-Fi memory corruption flaw (CVE-2026-28662) enabling remote code execution without privileges or user interaction.

SecurityWeek · 6d agoAdvisoryCVE-2026-28662

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google's September 2026 Android bulletin fixes over 30 critical flaws, including no-interaction system RCEs, a TIPC kernel RCE and a Qualcomm closed-source bug

Google's Android Security Bulletin for September 2026 (patch levels 2026-09-01 and 2026-09-05) fixes numerous critical System remote code execution flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919 and CVE-2026-49921, none requiring user interaction or additional privileges. It also addresses critical kernel issues including a TIPC RCE (CVE-2026-52993) and elevation-of-privilege flaws in NFC and protected KVM, plus a critical Qualcomm closed-source component flaw (CVE-2026-25289). Affected versions span Android 14 through 17; the 2026-09-05 patch level extends coverage to Android TV and chipset components, with high-severity fixes for Arm Mali, PowerVR, MediaTek, Unisoc and Qualcomm components.