Qualcomm warns of three zero-day vulnerabilities in GPU and Compute DSP drivers, which are being actively exploited by malicious actors for attacks.
See also: Qualcomm will supply Apple with 5G chips until 2026!

The American company received an update from Google 's Threat Analysis Team (TAG) and Project Zero that vulnerabilities CVE-2023-33106, CVE-2023-33107, CVE-2022-22071 and CVE-2023-33063 may be used in limited, targeted attacks.
Qualcomm has announced the release of security updates that address issues in its Adreno GPU and Compute DSP drivers . Additionally, affected OEMs have been notified.
The flaw CVE-2022-22071 was disclosed in May 2022. This flaw has a high severity (CVSS v3.1: 8.4) and can be exploited locally through bugs affecting popular chips such as the SD855, SD865 5G, and SD888 5G.
Qualcomm has not announced details about the vulnerabilities CVE-2023-33106, CVE-2022-22071, and CVE-2023-33063 that have been activated, but will provide more information via the December 2023 bulletin.
This month's security bulletin warns of three other critical vulnerabilities:
CVE-2023-24855: Memory corruption in Qualcomm modem component occurs when processing security-related configurations before AS Security Exchange. (CVSS v3.1:9.8)
CVE-2023-28540: Cryptographic issue in the data modem component resulting from improper authentication during the TLS handshake. (CVSS v3.1:9.1)
CVE-2023-33028: Memory corruption in WLAN firmware that occurs when copying the pmk cache without performing size checks. (CVSS v3.1:9.8)
See also: Qualcomm: Its new chips want to bring the power of Steam Deck to Android

Beyond these, Qualcomm disclosed 13 serious flaws and three high-severity critical vulnerabilities that its engineers identified.
As the flaws CVE-2023-24855, CVE-2023-2854 and CVE-2023-33028 are all remotely executable, they are considered critical from a security perspective. However, there is no evidence of any exploitation. Unfortunately, affected consumers have limited options other than to apply the available updates as soon as they are received through OEM channels.
Driver vulnerabilities typically require local access to exploit and are usually achieved through malware infections . For this reason, Android device owners are advised to limit the number of apps they download and only choose trusted software sources.
See also: Sony and Qualcomm expand their partnership for new smartphones
Zero-days are vulnerabilities in software that have not yet been discovered by the software manufacturer and have not been released in updates or patches. These vulnerabilities can be exploited by malicious hackers to cause damage or gain access to systems without the user's consent. These vulnerabilities can be in various parts of the software, such as the application code, the operating system, or device drivers. When hackers discover a zero-day vulnerability, they exploit it before the software manufacturer knows about it and before it has been patched.
