Skip to main content

Broadcom Wi-Fi Stack Vulnerability

Researchers from Google's Project Zero have discovered vulnerabilities in Broadcom's Wi-Fi chips which can allow a remote attacker to gain code execution on the chip with the added possibility of privilege escalation into the operating system kernel.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Researchers from Google's Project Zero have discovered vulnerabilities in Broadcom's Wi-Fi chips which can allow a remote attacker to gain code execution on the chip with the added possibility of privilege escalation into the operating system kernel.

Threat details

The attack is based on a buffer overflow on the Wi-Fi stack which affects a plethora of smartphones including Apple iPhones 5 through to 7 and many Android devices, including Google's Nexus and Samsung's Galaxy.

The vulnerable 'FullMAC' standalone Wi-Fi chips have been introduced on mobile devices to handle more complex Wi-Fi features and take some of the work load off the application processor, helping to extend battery life and speeding up operations.

The researchers found two variants of a stack overflow in Broadcom's Wi-Fi SoC (Systems-on-Chip). The first occurred during the handling of the IEEE 802.11r Fast BSS Transition Feature's authentication response while the second can be triggered when Cisco's proprietary CCKM Fast and Secure Roaming feature parsed a re-association response.

Patches released this week for Android and iOS draw attention to one of the softer targets powering our mobile devices: increasingly complex but not so well defended, Wi-Fi chips.


Remediation steps

Type Step
  • Apply security patches at the earliest opportunity

Last edited: 17 February 2020 11:27 am