Article Details

Scrape Timestamp (UTC): 2023-10-03 16:41:19.648

Source: https://thehackernews.com/2023/10/qualcomm-releases-patch-for-3-new-zero.html

Original Article Text

Click to Toggle View

Qualcomm Releases Patch for 3 new Zero-Days Under Active Exploitation. Chipmaker Qualcomm has released security updates to address 17 vulnerabilities in various components, while warning that three other zero-days have come under active exploitation. Of the 17 flaws, three are rated Critical, 13 are rated High, and one is rated Medium in severity. "There are indications from Google Threat Analysis Group and Google Project Zero that CVE-2023-33106, CVE-2023-33107, CVE-2022-22071, and CVE-2023-33063 may be under limited, targeted exploitation," the semiconductor company said in an advisory. "Patches for the issues affecting Adreno GPU and Compute DSP drivers have been made available, and OEMs have been notified with a strong recommendation to deploy security updates as soon as possible." CVE-2022-22071 (CVSS score: 8.4), described as a use-after-free in Automotive OS Platform, was originally patched by the company as part of its May 2022 updates. While additional specifics about the remaining other flaws are expected to be made public in December 2023, the disclosure comes the same day Arm shipped patches for a security flaw in the Mali GPU Kernel Driver (CVE-2023-4211) that has also come under limited, targeted exploitation. Qualcomm's October 2023 updates also address three critical issues, although there is no evidence that they have been abused in the wild - Users are advised to apply updates from original equipment manufacturers (OEMs) as soon as they become available.

Daily Brief Summary

MALWARE // Qualcomm Patches 17 Vulnerabilities including Zero-Days Under Active Exploitation

Qualcomm has released a security update fixing 17 vulnerabilities, including several that are under active exploitation.

Out of 17, three have been rated critical, 13 are rated high, and one is rated medium in severity.

According to Google's threat analysis groups, four codes (CVE-2023-33106, CVE-2023-33107, CVE-2022-22071, and CVE-2023-33063) could be under targeted exploitation.

The company has issued patches concerning Adreno GPU and Compute DSP drivers. Original Equipment Manufacturers (OEMs) have been strongly advised to carry out these security updates as quickly as possible.

CVE-2022-22071, which is a use-after-free in Automotive OS Platform, was first patched by Qualcomm in its May 2022 updates.

Further specific information regarding the remaining vulnerabilities will be made public in 2023.

Alongside Qualcomm's security measures, Arm also released patches for a security flaw in the Mali GPU kernel driver that had limited, targeted exploitation.