Google is warning about the active exploitation of a vulnerability affecting the Android.

The vulnerability, tracked as CVE-2024-43093, is located in the Android Framework component and is an elevation of privilege. Successful exploitation would allow unauthorized access to the “Android/data”, “Android/obb” and “Android/sandbox” directories and their subdirectories.
Google said there is evidence of limited, targeted exploitation of the Android vulnerability, but did not provide further details on how it is being used in actual attacks.
See also: Researchers uncover six vulnerabilities in Ollama AI framework
The company also said that the CVE-2024-43047 is now being used in attacks. It is worth noting that this vulnerability has now been patched in Qualcomm chipsets. Successful exploitation could lead to memory corruption.
Currently, it is not known whether the two vulnerabilities have been used together, as an exploit chain, to escalate privileges on systems and execute malicious code.
The CVE-2024-43093 vulnerability is the second vulnerability affecting the Android Framework to be actively exploited in attacks, following CVE-2024-32896, which was patched in June and September 2024. While initially only resolved for Pixel devices, the company later confirmed that the bug affected the wider Android ecosystem.
See also: Google found Zero-Day vulnerability in SQLite Database Engine

Android device protection
To protect your Android device, remember to regularly update your software and all apps. These updates address vulnerabilities that could put you at risk. Also, lock your screen, watch out for suspicious apps and phishing emails and messages, and use tools like VPN and two-factor authentication to protect your personal information and data. Stay vigilant and take proactive steps to keep your device safe from cyber threats.
See also: Okta Verify Agent Vulnerability Allows Password Theft
Additionally, it is important to stay informed about new vulnerabilities and threats targeting Android devices. Don’t wait until you become a victim of a cyberattack – start protecting your device now!
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
