In its November 2024 security update, Google fixed 40 vulnerabilities in Android, including two that are actively exploited: CVE-2024-43047 and CVE-2024-43093.
Google’s announcement gives minimal information about the exploitation, stating only that “there are indications that the following may be under limited, targeted exploitation.”
By F2
/ Thursday , July 3 2025
The final day of the Cyber Defence & Security Exhibition and Conference (CYDES) 2025 concluded with high-impact engagements at the...
Read More
By F2
/ Thursday , July 3 2025
Cisco warns that a vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition...
Read More
By F2
/ Wednesday , July 2 2025
The second day of the Cyber Defence & Security Exhibition and Conference (CYDES) 2025 further cemented Malaysia’s position as a...
Read More
By F2
/ Tuesday , July 1 2025
Malaysia's Deputy Prime Minister Datuk Seri Dr. Ahmad Zahid Hamidi said that Malaysia has placed cybersecurity at the heart of...
Read More
By F2
/ Tuesday , July 1 2025
Mark Chen, the chief research officer at OpenAI, sent a forceful memo to staff on Saturday, promising to go head-to-head...
Read More
By F2
/ Tuesday , July 1 2025
The Canadian government ordered Hikvision to stop all operations in the country due to national security concerns. Hikvision, based in...
Read More
By infosecbulletin
/ Sunday , June 29 2025
Doctors at Columbia University Fertility Center have reported what they are calling the first pregnancy using a new AI system,...
Read More
By infosecbulletin
/ Saturday , June 28 2025
Cybersecurity experts and federal authorities are warning that the Scattered Spider hackers are now targeting aviation and transportation, indicating a...
Read More
By F2
/ Saturday , June 28 2025
Since June 9, 2025, Russian users connecting to Cloudflare services have faced throttling by ISPs. As the throttling is being...
Read More
By infosecbulletin
/ Saturday , June 28 2025
A new report from SafetyDetectives reveals that hackers posted a massive 3.1GB dataset online, containing about 61 million records reportedly...
Read More
CVE-2024-43047 is a critical vulnerability (CVSS 7.8) found in Qualcomm’s Digital Signal Processor (DSP) service. Discovered by Google Project Zero, Amnesty International’s Security Lab, and researcher Conghui Wang, this zero-day issue affects many Qualcomm chipsets. Exploiting this use-after-free vulnerability could allow attackers to gain higher privileges and compromise devices. Qualcomm released a patch in October, and its inclusion in the November Android security update will ensure wider distribution and fixes.
The update is crucial due to the active exploitation of CVE-2024-43093, a privilege escalation vulnerability affecting Android versions 12, 13, 14, and 15. This flaw puts a large part of the Android ecosystem at risk.
In typical fashion, Google is delivering the update in two patch levels:
November 1 Patch Level (2024-11-01): Focuses on important Android parts, like the system and framework.
November 5 Patch Level (2024-11-05): Targets vulnerabilities in specific hardware components, including those from Qualcomm, MediaTek, and Imagination Technologies.
Android users should install the November security update immediately when it’s available. Quick action is essential to protect against the active exploitation of vulnerabilities.