Google fixes two Android zero-days used in targeted attacks

Teilen:

Google fixed two actively exploited Android zero-day flaws as part of its November security updates, addressing a total of 51 vulnerabilities.

Tracked as CVE-2024-43047 and CVE-2024-43093, the two issues are marked as exploited in limited, targeted attacks.

“There are indications that the following may be under limited, targeted exploitation,” says Google’s advisory.

The CVE-2024-43047 flaw is a high-severity use-after-free issue in closed-source Qualcomm components within the Android kernel that elevates privileges.

The flaw was first disclosed in early October 2024 by Qualcomm as a problem in its Digital Signal Processor (DSP) service.

CVE-2024-43093 is also a high-severity elevation of privilege flaw, this time impacting the Android Framework component and Google Play system updates, specifically in the Documents UI.

Google did not disclose who discovered the CVE-2024-43093 vulnerability.

While Google did not share any details on how the vulnerabilities were exploited, as researchers at Amnesty International discovered CVE-2024-43047, it could indicate that the flaw was used in targeted spyware attacks.

Out of the remaining 49 flaws fixed this time, only one, CVE-2024-38408, is classified as critical, also impacting Qualcomm’s proprietary components.

The security issues fixed this month impact Android versions between 12 and 15, with some being limited to specific versions of the mobile operating system.

Google issues two patch levels each month, in this case, November 1 (2024-11-01 Patch Level) and November 5 (2024-11-05 Patch Level).

The first level addresses core Android vulnerabilities, with 17 issues this time, while the second patch level encompasses those plus vendor-specific fixes (Qualcomm, MediaTek, etc.), counting an additional 34 fixes this month.

To apply the latest update, head to Settings > System > Software updates > System update. Alternatively, go to Settings > Security & privacy > System & updates > Security update. A restart will be required to apply the update.

Android 11 and older are no longer supported but may receive security updates to critical issues for actively exploited flaws through Google Play system updates, though that’s not guaranteed.

The best course of action for devices still running those older releases should be either to replace them with newer models or use a third-party Android distribution that incorporates the latest security fixes.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:52 pm, März 9, 2025
Wetter-Symbol 18°C
L: 16° | H: 19°
broken clouds
Luftfeuchtigkeit: 46 %
Druck: 1002 mb
Wind: 8 mph SE
Windböe: 14 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 52%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:28 am
Sonnenuntergang: 5:54 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
16° | 19°°C 0 mm 0% 8 mph 62 % 1003 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
10° | 15°°C 0 mm 0% 7 mph 70 % 1007 mb 0 mm/h
Di. März 11 9:00 pm
Wetter-Symbol
5° | 8°°C 0 mm 0% 10 mph 85 % 1008 mb 0 mm/h
Mi. März 12 9:00 pm
Wetter-Symbol
3° | 6°°C 1 mm 100% 9 mph 80 % 1006 mb 0 mm/h
Do. März 13 9:00 pm
Wetter-Symbol
2° | 8°°C 0.2 mm 20% 10 mph 91 % 1005 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
16° | 18°°C 0 mm 0% 8 mph 46 % 1002 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
14° | 16°°C 0 mm 0% 4 mph 51 % 1002 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
11° | 14°°C 0 mm 0% 4 mph 62 % 1003 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 4 mph 66 % 1002 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 3 mph 65 % 1001 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 5 mph 70 % 1002 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 7 mph 65 % 1003 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 6 mph 47 % 1004 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€77,749.30
-2.34%
Ethereum(ETH)
€1,968.76
-2.29%
Fesseln(USDT)
€0.92
0.01%
XRP(XRP)
€2.04
-5.69%
Solana(SOL)
€123.81
-2.65%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.169256
-6.13%
Shiba Inu(SHIB)
€0.000011
-4.45%
Pepe(PEPE)
€0.000006
-7.88%