Hackers targeted Android users by exploiting zero-day bug in Qualcomm chips

On Monday, chipmaker Qualcomm confirmed that hackers exploited a zero-day — meaning a security flaw that was unknown to the hardware maker when it was abused — in dozens of its chipsets found in popular Android devices.

The zero-day vulnerability, officially designated CVE-2024-43047, “may be under limited, targeted exploitation,” according to Qualcomm, citing unspecified “indications” from Google’s Threat Analysis Group, the company’s research unit that investigates government hacking threats. Amnesty International’s Security Lab, which works to protect civil society from digital surveillance and spyware threats, confirmed Google’s assessment, Qualcomm said.

U.S. cybersecurity agency CISA included the Qualcomm flaw in its list of vulnerabilities that are known to be, or have been, exploited.

At this point, there aren’t many details about who was exploiting this vulnerability “in the wild” — meaning that whoever was using the zero-day was targeting individuals in real hacking campaigns. It also is not yet known which individuals were targeted, or why.

Qualcomm’s spokesperson Catherine Baker told TechCrunch that the company commends “the researchers from Google Project Zero and Amnesty International Security Lab for using coordinated disclosure practices,” allowing the company to roll out fixes for the vulnerability.

The chipmaker referred to Amnesty and Google for more details about the threat activity.

Amnesty spokesperson Hajira Maryam told TechCrunch that the nonprofit will have research about this vulnerability “due to be out soon.”

Google spokesperson Kimberly Samra said TAG has nothing to add at the moment.

Qualcomm’s spokesperson said that “fixes have been made available to our customers as of September 2024.” It’s now up to Qualcomm’s customers — the Android device makers that use the vulnerable chipsets — to release the patch to their customers’ devices.

In its advisory, Qualcomm listed 64 different chipsets affected by this vulnerability, including the company’s flagship Snapdragon 8 (Gen 1) mobile platform, which is used in dozens of Android phones, including some made by Motorola, Samsung, OnePlus, Oppo, Xiaomi, and ZTE — meaning millions of users around the world are potentially vulnerable.

That being said, the fact that Google and Amnesty are investigating the use of this zero-day under “limited, targeted exploitation” suggests the hacking campaign was likely used against specific individuals, rather than a large number of targets.

Next Page

Project Management
08.10.2024

Guide to Project Management Software Pricing Models

Project managers rely on project management (PM) software to simplify and automate crucial tasks to enhance the efficiency and productivity of their projects.

connect with us

Please fill out the form below and we will
contact you shortly.

form-image

What services are you interested in?

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. By submitting, I agree to DigiTech Services OÜ Privacy Notice.

form-image

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site we will assume that you are happy with it.