
Google has come with a warning about a vulnerability in the Android OS that is actively exploited in the wild.
The vulnerability tracked as CVE-2024-43093, with a CVSS score of 5.4 is a privilege escalation issue in the Android Framework component. Successful exploitation of the vulnerability could lead to unauthorized access to “Android/data,” “Android/obb,” and “Android/sandbox” directories and associated sub-directories.
Google as usual did not share details about the attacks exploiting the above vulnerability, however, it added that another issue, tracked as CVE-2024-43047, is actively exploited in the wild.
As per the bulletin, there are indications that the following may be under limited, targeted exploitation.
- CVE-2024-43093
- CVE-2024-43047
The vulnerability CVE-2024-43047 is a kernel issue in the Qualcomm components. The issue is a potential use-after-free (UAF) vulnerability in the way the DSP (Digital Signal Processor) handles Direct Memory Access (DMA) file descriptors (FDs) in its header buffers. Successful exploitation can lead to memory corruption.
Both vulnerabilities are under limited, targeted exploitation, Google states.
For more information, refer to the blog

