Qualcomm has released security updates for a zero-day vulnerability in its Digital Signal Processor (DSP), which affects dozens of chipsets.

The vulnerability is tracked as CVE-2024-43047 and was reported by Seth Jenkins of Google Project Zero and Conghui Wang of Amnesty International's security lab. It is a use-after-free issue that can cause memory corruptionif successfully exploited by local attackers with low privileges.
See also: Okta: Possible exploitation of recently patched vulnerability
According to Qualcomm, researchers have reported that the vulnerability is already being used in attacks. Researchers from both Google and Amnesty International are discovering zero-day bugs, which are commonly used in spyware and target the mobile devices of high-risk individuals, including journalists, opposition politicians and dissidents.
Qualcomm said that updates for the issue affecting the FASTRPC driver have been made available to OEMs and it is recommended that the update be deployed as soon as possible.
Qualcomm also urged users to contact their device manufacturer to learn more details about the patch status of their devices.
See also: Warning! Critical vulnerability in Apache Avro Java SDK
The company also fixed another serious vulnerability (CVE-2024-33066) in WLAN Resource Manager, which was reported more than a year ago and could also cause memory corruption.

These vulnerabilities highlight the importance of promptly applying security updates. Qualcomm has strongly recommended that all users apply the latest update to protect devices from potential exploitation. As previously stated, the company works closely with device manufacturers and vendors to ensure the rapid distribution of these fixes. Users are advised to regularly check for system updates and install them promptly to maintain optimal security.
This situation serves as a stark reminder of the need for vigilance, highlighting the role of companies technology and the research community in protecting end users.
See also: LiteSpeed Cache WordPress: New vulnerability allows XSS attacks
As technology continues to advance and become more integrated into our daily lives, the need for strong security becomes increasingly important.
Source: www.bleepingcomputer.com
