BlackHat Reveals Critical WiFi 7 Bug Missed by Both LLMs and Human Auditors

chrisrohlf · x · 2026-08-03

During BlackHat/DEF CON week, a security researcher disclosed a critical WiFi 7 memory corruption bug in Hostapd, the userland daemon powering the majority of the world's WiFi access points.

The flaw was reported in June and is now patched upstream. The researcher's proof of concept demonstrates that authenticated clients can bypass ASLR to leak pointers OTA and inject code execution. Because of the "outer tunnel," 802.1X Enterprise WiFi 7 is essentially exploitable pre-authentication.

Notably, the bug was missed by both human auditors and LLM scans, and was ultimately caught by the "wifi gauntlet."

Original post →

More from Safety

Safety channel →