Qualcomm Urges OEMs to Patch Critical DSP and WLAN Flaws Amid Active Exploits
Over two dozen vulnerabilities affecting both proprietary and open-source components have been fixed by Qualcomm through security upgrades, one of which is currently being actively exploited in the field.
According to descriptions, the high-severity vulnerability in the Digital Signal Processor (DSP) Service, identified as CVE-2024-43047 (CVSS score: 7.8), is a user-after-free flaw that may cause memory corruption while preserving memory maps of HLOS memory.
Qualcomm said that Amnesty International Security Lab verified in-the-wild activities and that researchers Seth Jenkins and Conghui Wang of Google Project Zero were responsible for exposing the vulnerabilities.
According to a warning from the chipmaker, Google Threat Analysis Group has found signs that CVE-2024-43047 is poten...

