• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
qualcomm releases details on chip vulnerabilities exploited in targeted attacks

Qualcomm Releases Details on Chip Vulnerabilities Exploited in Targeted Attacks

You are here: Home / General Cyber Security News / Qualcomm Releases Details on Chip Vulnerabilities Exploited in Targeted Attacks
December 6, 2023

Chipmaker Qualcomm has produced a lot more information and facts about three large-severity security flaws that it reported came beneath “restricted, targeted exploitation” again in October 2023.

The vulnerabilities are as follows –

  • CVE-2023-33063 (CVSS rating: 7.8) – Memory corruption in DSP Solutions during a distant connect with from HLOS to DSP.
  • CVE-2023-33106 (CVSS score: 8.4) – Memory corruption in Graphics when publishing a big checklist of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
  • CVE-2023-33107 (CVSS score: 8.4) – Memory corruption in Graphics Linux though assigning shared virtual memory region through IOCTL connect with.

Google’s Threat Investigation Team and Google Task Zero disclosed back in Oct 2023 that the three flaws, alongside with CVE-2022-22071 (CVSS score: 8.4), have been exploited in the wild as portion of restricted, specific attacks.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

A security researcher named luckyrb, the Google Android Security team, and TAG researcher Benoît Sevens and Jann Horn of Google Challenge Zero have been credited with reporting the security vulnerabilities, respectively.

It’s at present not known how these shortcomings have been weaponized, and who are guiding the attacks.

The improvement, having said that, has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to incorporate the four bugs to its Regarded Exploited Vulnerabilities (KEV) catalog, urging federal agencies to implement the patches by December 26, 2023.

It also follows Google’s announcement that the December 2023 security updates for Android deal with 85 flaws, like a critical issue in the Program ingredient tracked as CVE-2023-40088 that “could lead to remote (proximal/adjacent) code execution with no more execution privileges required” and with out any consumer conversation.

Uncovered this write-up interesting? Abide by us on Twitter  and LinkedIn to study more unique content material we submit.


Some components of this article are sourced from:
thehackernews.com

Previous Post: «russia's ai powered disinformation operation targeting ukraine, u.s., and germany Russia’s AI-Powered Disinformation Operation Targeting Ukraine, U.S., and Germany
Next Post: Atlassian Releases Critical Software Fixes to Prevent Remote Code Execution atlassian releases critical software fixes to prevent remote code execution»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms
  • Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; $90M Stolen in Crypto Heist
  • 6 Steps to 24/7 In-House SOC Success
  • Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider
  • 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers
  • New Android Malware Surge Hits Devices via Overlays, Virtualization Fraud and NFC Theft
  • BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
  • Secure Vibe Coding: The Complete New Guide
  • Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Session
  • Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Copyright © TheCyberSecurity.News, All Rights Reserved.