In its November 2024 security update, Google fixed 40 vulnerabilities in Android, including two that are actively exploited: CVE-2024-43047 and CVE-2024-43093.
Google’s announcement gives minimal information about the exploitation, stating only that “there are indications that the following may be under limited, targeted exploitation.”
By infosecbulletin
/ Monday , June 22 2026
The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
By infosecbulletin
/ Monday , June 22 2026
Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
By infosecbulletin
/ Sunday , June 21 2026
AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
By infosecbulletin
/ Sunday , June 21 2026
Brazil's government suspects a hacking attack triggered an unauthorized alert sent to cell phones across parts of the country early...
Read More
By infosecbulletin
/ Sunday , June 21 2026
A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
By infosecbulletin
/ Saturday , June 20 2026
Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
By infosecbulletin
/ Saturday , June 20 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
By infosecbulletin
/ Saturday , June 20 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to protect their systems by Sunday from a...
Read More
By infosecbulletin
/ Saturday , June 20 2026
The Texas Parks and Wildlife Department (TPWD) revealed a data leak at its license system provider. This leak exposed private...
Read More
By infosecbulletin
/ Friday , June 19 2026
Cisco has revealed critical security flaws in its Identity Services Engine (ISE). These flaws could let attackers run harmful code...
Read More
CVE-2024-43047 is a critical vulnerability (CVSS 7.8) found in Qualcomm’s Digital Signal Processor (DSP) service. Discovered by Google Project Zero, Amnesty International’s Security Lab, and researcher Conghui Wang, this zero-day issue affects many Qualcomm chipsets. Exploiting this use-after-free vulnerability could allow attackers to gain higher privileges and compromise devices. Qualcomm released a patch in October, and its inclusion in the November Android security update will ensure wider distribution and fixes.
The update is crucial due to the active exploitation of CVE-2024-43093, a privilege escalation vulnerability affecting Android versions 12, 13, 14, and 15. This flaw puts a large part of the Android ecosystem at risk.
In typical fashion, Google is delivering the update in two patch levels:
November 1 Patch Level (2024-11-01): Focuses on important Android parts, like the system and framework.
November 5 Patch Level (2024-11-05): Targets vulnerabilities in specific hardware components, including those from Qualcomm, MediaTek, and Imagination Technologies.
Android users should install the November security update immediately when it’s available. Quick action is essential to protect against the active exploitation of vulnerabilities.