Threat Advisory

New Wi-Fi Authentication Bypass Flaw in Android, Linux, and ChromeOS Devices

Threat: Vulnerability
Threat Actor Type: NA
Targeted Region: NA
Threat Actor Region: NA
Targeted Sector: NA
Criticality: High
[subscribe_to_unlock_form]

Summary:

Security researchers have discovered two authentication bypass vulnerabilities, CVE-2023-52160 and CVE-2023-52161, in open-source Wi-Fi software commonly used in Android, Linux, and ChromeOS devices. These flaws could allow attackers to trick users into connecting to malicious networks or gain unauthorized access to trusted networks.[/subscribe_to_unlock_form]

Summary:

Security researchers have discovered two authentication bypass vulnerabilities, CVE-2023-52160 and CVE-2023-52161, in open-source Wi-Fi software commonly used in Android, Linux, and ChromeOS devices. These flaws could allow attackers to trick users into connecting to malicious networks or gain unauthorized access to trusted networks.[emaillocker id="1283"]

  • CVE-2023-52160 (Phase-2 bypass): This vulnerability impacts wpa_supplicant versions 2.10 and earlier, the default software used in Android devices for handling wireless network logins. It primarily affects Wi-Fi clients that lack proper authentication server certificate verification but could be exploited in specific scenarios where an attacker is in physical proximity to a victim.
  • CVE-2023-52161 (4-way bypass): This vulnerability affects Intel's iNet Wireless Daemon (IWD) versions 2.12 and below. Attackers exploiting this flaw can gain unauthorized access to protected Wi-Fi networks, potentially leading to malware infections, data theft, and business email compromise (BEC).

Both vulnerabilities pose significant risks, especially in environments using Android, Linux, or ChromeOS. Major Linux distributions have released advisories, and the issue has been addressed in ChromeOS versions 118 and later. However, Android fixes are pending, making it crucial for users to manually configure CA certificates for saved enterprise networks.

Recommendations:

  • We strongly recommend you update Intel's iNet Wireless Daemon (IWD)  to version 2.14-1 and wpa_supplicant to version 2.11.

References:

The following reports contain further technical details:

https://cybersecuritynews.com/new-wi-fi-authentication-bypass-flaw/

https://thehackernews.com/2024/02/new-wi-fi-vulnerabilities-expose.html

[/emaillocker]
crossmenu