Google patches actively exploited Android vulnerability (CVE-2024-43093)

Teilen:

Google has delivered fixes for two vulnerabilities endangering Android users that “may be under limited, targeted exploitation”: CVE-2024-43047, a flaw affecting Qualcomm chipsets, and CVE-2024-43093, a vulnerability in the Google Play framework.

The exploited vulnerabilities (CVE-2024-43047, CVE-2024-43093)

Qualcomm patched CVE-2024-43047 – a use-after-free vulnerability in the Digital Signal Processor (DSP) service that could be exploited to escalate privileges on targeted devices – in October 2024, and urged original equipment manufacturers (OEMs) to deploy the patches as soon as possible.

Reported by Seth Jenkins of Google Project Zero and Conghui Wang of Amnesty International Security Lab, it’s highly likely that the flaw is being leveraged by commercial mobile spyware makers.

Also, “limited, targeted exploitation” is phrasing that usually points toward cyber espionage campaigns rather than broad malware attacks and often implicates the use of specialized spyware targeting activists, journalists, or dissidents.

CVE-2024-43093 is another vulnerability that allows privilege escalation and has been fixed by restricting access to “Android/data,” “Android/obb,” and “Android/sandbox” directories and their sub-directories.

Propagating fixes in the Android ecosystem

As per usual, the Android Security Bulletin for November 2024 contains fixes for many other flaws found in the Android platform.

Android partners are notified of all issues at least a month before publication of each monthly Android security bulletin, and source code patches for them are released to the Android Open Source Project (AOSP) repository.

Samsung has, for example, patched CVE-2024-43047 in the October 2024 maintenance release for major flagship models, and CVE-2024-43093 in the one made available in November 2024.

Zeljka Zorz

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:04 pm, Feb. 2, 2025
Wetter-Symbol 8°C
L: 7° | H: 10°
klarer Himmel
Luftfeuchtigkeit: 70 %
Druck: 1022 mb
Wind: 7 mph S
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 6%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:37 am
Sonnenuntergang: 4:51 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 10°°C 0 mm 0% 6 mph 76 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
2° | 9°°C 0 mm 0% 9 mph 89 % 1025 mb 0 mm/h
Di. Feb. 04 9:00 pm
Wetter-Symbol
7° | 11°°C 0.2 mm 20% 13 mph 89 % 1027 mb 0 mm/h
Mi. Feb. 05 9:00 pm
Wetter-Symbol
4° | 8°°C 0 mm 0% 10 mph 84 % 1045 mb 0 mm/h
Do. Feb. 06 9:00 pm
Wetter-Symbol
2° | 8°°C 0 mm 0% 8 mph 84 % 1045 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 6 mph 70 % 1022 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
5° | 7°°C 0 mm 0% 3 mph 71 % 1023 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
4° | 5°°C 0 mm 0% 3 mph 76 % 1025 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 81 % 1025 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 84 % 1025 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 85 % 1025 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 85 % 1025 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 7 mph 80 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,299.99
-3.05%
Ethereum(ETH)
€2,977.75
-4.94%
XRP(XRP)
€2.72
-5.61%
Fesseln(USDT)
€0.96
-0.02%
Solana(SOL)
€205.06
-6.58%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.286503
-7.93%
Shiba Inu(SHIB)
€0.000016
-7.27%
Pepe(PEPE)
€0.000012
-8.77%
Nach oben scrollen