Your Android device is vulnerable to attack and Google’s fix is imminent
Jack Wallen/ZDNETIf you follow the Android Security Bulletin, then you might have noticed a listing for the November security patch level that includes two critical vulnerabilities, which are:CVE-2024-43047CVE-2024-43093According to the bulletin, “There are indications that the following may be under limited, targeted exploitation.”Also: An anti-theft upgrade is coming to Android phones. Here’s how to see if you have it yetThe first of those vulnerabilities, CVE-2024-43047, is described as “memory corruption while maintaining memory maps of HLOS memory.” CVE-2024-43047 affects the Qualcomm Digital Signal Processor (DSP) service, which impacts several Qualcomm chipsets and can lead to memory corruption and enable attackers to escalate privileges and compromise affected devices. Qualcomm issued a patch for this vulnerability back in October, and it has been included in the November Android Security Update to provide wider distribution and remediation.The second CVE issue is 2024-43093, which is an escalation of privilege vulnerability that affects Android’s framework component in versions 12, 13, 14, and 15 and can lead to exposing a significant portion of Android to attack. More