GOOG-16-010500 - The Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps.

Information

Wi-Fi Aware allows direct connections between nearby devices for fast data transfer, video streaming, and multiplayer gaming. It allows full peer-to-peer device discovery and communication where two or more devices are publishing and/or subscribing to the same known service name. There is risk that sensitive DOD information could be transferred from a DOD mobile device to a non-DOD device or from Work Profile apps on a DOD device to Personal Profile apps on a non-DOD device.

Solution

Configure the Google Android 16 device to disable Wi-Fi Aware for all Work Profile apps.

On the EMM console:

For each Work Profile app, configure the NEARBY_WIFI_DEVICE permission to 'deny' to block the use of Wi-Fi Aware, if the app supports this feature. If the app does not support Wi-Fi Aware, there may not be a NEARBY_WIFI_DEVICE permission available.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Android_16_Y25M08_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-276775r1140673_rule, STIG-ID|GOOG-16-010500, Vuln-ID|V-276775

Plugin: MDM

Control ID: a2e382f7b42b6f0519ef6fae56f9ee8a10c76f463223b06a96c460688d19e6fb