Summary:
Security researchers have discovered two authentication bypass vulnerabilities, CVE-2023-52160 and CVE-2023-52161, in open-source Wi-Fi software commonly used in Android, Linux, and ChromeOS devices. These flaws could allow attackers to trick users into connecting to malicious networks or gain unauthorized access to trusted networks.[/subscribe_to_unlock_form]
Summary:
Security researchers have discovered two authentication bypass vulnerabilities, CVE-2023-52160 and CVE-2023-52161, in open-source Wi-Fi software commonly used in Android, Linux, and ChromeOS devices. These flaws could allow attackers to trick users into connecting to malicious networks or gain unauthorized access to trusted networks.[emaillocker id="1283"]
Both vulnerabilities pose significant risks, especially in environments using Android, Linux, or ChromeOS. Major Linux distributions have released advisories, and the issue has been addressed in ChromeOS versions 118 and later. However, Android fixes are pending, making it crucial for users to manually configure CA certificates for saved enterprise networks.
Recommendations:
References:
The following reports contain further technical details:
https://cybersecuritynews.com/new-wi-fi-authentication-bypass-flaw/
https://thehackernews.com/2024/02/new-wi-fi-vulnerabilities-expose.html
[/emaillocker]