Out of Bounds Read Vulnerability in Android IEEE 802.11 Products
CVE-2026-49895

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-49895?

A potential out of bounds read vulnerability exists in the get_eht_operation_channel_width function within ieee802_11_common.c in Android's IEEE 802.11 implementations. This vulnerability arises from an improper bounds check, which may enable adjacent attackers to exploit the flaw. The exploitation does not require any additional privileges or user interaction, leading to possible remote information disclosure.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.