Google patches actively exploited Android vulnerability (CVE-2024-43093)

Teilen:

Google has delivered fixes for two vulnerabilities endangering Android users that “may be under limited, targeted exploitation”: CVE-2024-43047, a flaw affecting Qualcomm chipsets, and CVE-2024-43093, a vulnerability in the Google Play framework.

The exploited vulnerabilities (CVE-2024-43047, CVE-2024-43093)

Qualcomm patched CVE-2024-43047 – a use-after-free vulnerability in the Digital Signal Processor (DSP) service that could be exploited to escalate privileges on targeted devices – in October 2024, and urged original equipment manufacturers (OEMs) to deploy the patches as soon as possible.

Reported by Seth Jenkins of Google Project Zero and Conghui Wang of Amnesty International Security Lab, it’s highly likely that the flaw is being leveraged by commercial mobile spyware makers.

Also, “limited, targeted exploitation” is phrasing that usually points toward cyber espionage campaigns rather than broad malware attacks and often implicates the use of specialized spyware targeting activists, journalists, or dissidents.

CVE-2024-43093 is another vulnerability that allows privilege escalation and has been fixed by restricting access to “Android/data,” “Android/obb,” and “Android/sandbox” directories and their sub-directories.

Propagating fixes in the Android ecosystem

As per usual, the Android Security Bulletin for November 2024 contains fixes for many other flaws found in the Android platform.

Android partners are notified of all issues at least a month before publication of each monthly Android security bulletin, and source code patches for them are released to the Android Open Source Project (AOSP) repository.

Samsung has, for example, patched CVE-2024-43047 in the October 2024 maintenance release for major flagship models, and CVE-2024-43093 in the one made available in November 2024.

Zeljka Zorz

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:14 pm, Apr. 21, 2025
Wetter-Symbol 13°C
L: 12° | H: 14°
overcast clouds
Luftfeuchtigkeit: 78 %
Druck: 1011 mb
Wind: 8 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:51 am
Sonnenuntergang: 8:06 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 14°°C 0 mm 0% 6 mph 83 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
8° | 17°°C 0 mm 0% 11 mph 93 % 1017 mb 0 mm/h
Mi. Apr. 23 10:00 pm
Wetter-Symbol
9° | 16°°C 1 mm 100% 15 mph 93 % 1016 mb 0 mm/h
Do. Apr. 24 10:00 pm
Wetter-Symbol
9° | 13°°C 0.2 mm 20% 4 mph 82 % 1022 mb 0 mm/h
Fr. Apr. 25 10:00 pm
Wetter-Symbol
8° | 16°°C 0 mm 0% 8 mph 89 % 1022 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
12° | 13°°C 0 mm 0% 6 mph 83 % 1012 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
10° | 11°°C 0 mm 0% 6 mph 88 % 1013 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
8° | 8°°C 0 mm 0% 5 mph 93 % 1015 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 4 mph 89 % 1016 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 7 mph 67 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 44 % 1017 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 36 % 1016 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 11 mph 55 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€75,414.51
2.75%
Ethereum(ETH)
€1,368.46
-0.20%
Fesseln(USDT)
€0.87
0.01%
XRP(XRP)
€1.80
0.61%
Solana(SOL)
€116.99
-1.19%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.136481
2.26%
Shiba Inu(SHIB)
€0.000010
-1.02%
Pepe(PEPE)
€0.000007
2.51%
Nach oben scrollen