Google fixes two Android zero-days used in targeted attacks
ID: 47c9da6e-0a6e-5c10-b0bc-926dddff86eb
STIX ID: report--47c9da6e-0a6e-5c10-b0bc-926dddff86eb
Feed Name: Bleeping Computer
Google's November 2024 Android security update fixes 51 vulnerabilities, including two actively exploited zero-days (CVE-2024-43047 and CVE-2024-43093) used in limited targeted attacks; CVE-2024-43047 is a Qualcomm closed-source kernel use-after-free that can elevate privileges, while CVE-2024-43093 affects the Android Framework/Documents UI and also allows privilege escalation. The bulletin covers Android 12–15 with vendor-specific fixes (Qualcomm, MediaTek), and users are advised to apply the November 1 and November 5 patch levels via System > Software updates or Security update; older devices on Android 11 and earlier may not receive full support and should be replaced or use updated third-party distributions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
