Article Details
Scrape Timestamp (UTC): 2023-12-06 11:11:58.039
Source: https://thehackernews.com/2023/12/qualcomm-releases-details-on-chip.html
Original Article Text
Click to Toggle View
Qualcomm Releases Details on Chip Vulnerabilities Exploited in Targeted Attacks. Chipmaker Qualcomm has released more information about three high-severity security flaws that it said came under "limited, targeted exploitation" back in October 2023. The vulnerabilities are as follows - Google's Threat Analysis Group and Google Project Zero revealed back in October 2023 that the three flaws, along with CVE-2022-22071 (CVSS score: 8.4), have been exploited in the wild as part of limited, targeted attacks. A security researcher named luckyrb, the Google Android Security team, and TAG researcher Benoît Sevens and Jann Horn of Google Project Zero have been credited with reporting the security vulnerabilities, respectively. It's currently not known how these shortcomings have been weaponized, and who are behind the attacks. The development, however, has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the four bugs to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to apply the patches by December 26, 2023. It also follows Google's announcement that the December 2023 security updates for Android address 85 flaws, including a critical issue in the System component tracked as CVE-2023-40088 that "could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed" and without any user interaction.
Daily Brief Summary
Qualcomm has disclosed information on three serious security flaws that faced targeted exploitation previously.
Google's teams identified the vulnerabilities, which were part of limited attacks, including CVE-2022-22071 with an 8.4 CVSS score.
Security professionals luckyrb, the Google Android Security team, and Google Project Zero members reported these security issues.
Specifics on how the vulnerabilities were exploited and the identities of the attackers remain undisclosed.
CISA has listed the vulnerabilities in its KEV catalog, mandating federal agencies to patch them by December 26, 2023.
The announcement comes as Google's December security updates for Android aim to resolve 85 different flaws, highlighting a critical system issue enabling code execution without user interaction.