pwshub.com

Qualcomm urges OEMs to patch after 'targeted' exploitation

Qualcomm has issued 20 patches for its chipsets' firmware, including one Digital Signal Processor (DSP) software flaw that has been exploited in the wild.

That vulnerability, CVE-2024-43047, carries a CVSS 7.8-out-of-10 severity rating, and was notably reported by both Google's Project Zero team and Amnesty International's code testers. The involvement of the latter indicates this bug has been exploited by either nation-state attackers or commercial surveillanceware vendors, or both.

"There are indications from Google Threat Analysis Group that CVE-2024-43047 may be under limited, targeted exploitation," Qualcomm said in its advisory for the updates. "Patches for the issue affecting the FASTRPC driver have been made available to OEMs together with a strong recommendation to deploy the update on affected devices as soon as possible."

Ie, those device makers need to push these fixes out to people's gadgets ASAP. Look out for updates to install and apply them.

So far, the CVE-2024-43047 flaw affects Snapdragon 660 and newer models, Qualcomm's 5G modems, and FastConnect 6700, 6800, 6900, and 7800 Wi-Fi/Bluetooth kit.

  • 'Critical' CUPS vulnerability chain easy to use for massive DDoS attacks
  • 'Patch yesterday': Zimbra mail servers under siege through RCE vuln
  • Rackspace internal monitoring web servers hit by zero-day
  • Extracting vendor promises won't fix cybersecurity. Extracting teeth might

Of the other 19 flaws, there's CVE-2024-33066, a critical improper input validation issue with the WLAN resource manager which has a CVSS score of 9.8. Luckily so far, to our knowledge, this hasn't been exploited yet.

Qualcomm also warned of two other high-severity vulnerabilities - CVE-2024-23369 and CVE-2024-33065. The latter, rated CVSS 8.4, involves memory corruption in the camera driver. Meanwhile, the former is a similar memory flaw, affecting the device's high-level operating system. The chipmaker also released two other patches for medium-severity bugs.

The remaining 14 patches comprise nine high-severity and five medium bugs. Seven cover WLAN operations, three fix issues in the DSP service, and there's a grab-bag of other code improvements - although some of them were noted around a year ago and are only now being fixed.

Qualcomm got its announcement out early today, and we're still waiting to see what Patch Tuesday will bring from Microsoft and others. ®

Source: theregister.com

Related stories
1 month ago - aw snap — Windows-on-Arm has gotten better, but we're still waiting for good budget PCs. Qualcomm ...
1 month ago - Back in February 2023, Qualcomm announced a high-profile partnership with Samsung and Google to develop new mixed reality technology. This new class of products would provide users with access to both augmented reality experiences and VR...
1 month ago - Anonymous sources familiar with the matter told Reuters that Qualcomm executives have been examining Intel's various design units for months to determine whether any would fit their product portfolio. Some segments are more enticing than...
1 month ago - Well into the first year of on-device generative AI on phones and laptops, Snapdragon chip maker Qualcomm looks toward the future.
2 weeks ago - Qualcomm has approached fellow US chipmaker Intel in recent days about a possible takeover, the Wall Street Journal reported Friday.Intel has...
Other stories
2 minutes ago - Plus: SAP re-patches a failed patch for critical-rated flaw Patch Tuesday It's the second Tuesday of the month, which means Patch Tuesday, bringing with it fixes for numerous flaws, bugs and vulnerabilities in major software. And this one...
38 minutes ago - Amazon's October Prime Day sale is finally here and the deals are coming in full force. Score great bargains on TVs, laptops, home essentials and so much more!
38 minutes ago - If you are a hot sleeper who doesn't want to spend too much on a mattress, the Cocoon chill mattress is worth considering.
38 minutes ago - Thanks to this epic Prime Day sale, you can upgrade your indoor and outdoor at-home viewing experience and save money doing it.
38 minutes ago - A portable speaker doesn't have to compromise on sound quality, as demonstrated by the Soundcore Motion Boom Plus.