CVE-2026-49878: Android wpa_supplicant vulnerability
Published Oct 5, 2026
·Updated
In wpashandlerobustavscsrecvaction of robustav.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
Android wpa_supplicant
Event History
Oct 5, 2026
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments should be included in initial triage?
The affected software identified is Android wpa_supplicant. The supplied information does not identify specific Android versions, devices, or configuration conditions.
2
Is user interaction required for exploitation?
No. The description states that user interaction is not needed.
3
Does the available information identify a temporary mitigation or a way to verify exposure?
No. It does not provide a workaround, configuration change, affected-version list, or detection guidance.