Target Industry
Indiscriminate, opportunistic targeting.
Overview
A high-security update has been issued by Google due to active exploitation of a vulnerability in the Android system for Pixel users. The issue, identified as CVE-2024-43093, is a privilege escalation flaw in the Android Framework component. There is also a related vulnerability, CVE-2024-43047, affecting Qualcomm chipsets which is also being actively exploited. These vulnerabilities are described as “limited, targeted attacks,” indicating that the exploits are aimed at specific individuals or groups rather than being widespread.
Impact
Currently this is aimed at Pixel users, however, there was a vulnerability found in the summer, which was patched for Pixel users. But Google later confirmed that the security flaw affects the entire Android ecosystem and not just specific devices.
CVE-2024-43093 is a privilege escalation flaw in the Android Framework component, allowing unauthorised access to certain directories like Android/data, Android/obb, and Android/sandbox. It impacts Android versions 12 to 152.
CVE-2024-43047 affects Qualcomm chipsets and is a use-after-free flaw in the Digital Signal Processor (DSP) Service, leading to memory corruption, allowing threat actors to escalate privileges and potentially take control of affected devices.
Exploitation
The Google advisory does not provide details on the exploit activity targeting the vulnerability or its timeline of exploitation. However, it is speculated that the vulnerability may have been used in highly targeted spyware attacks against civil society members.
Containment, Mitigations & Remediations
Android users should promptly install the November security update to protect their devices from actively exploited vulnerabilities. There are two patches available:
- 11th November Patch Level (2024-11-01): Focusing on core Android components, including the framework and system
- 5th November Patch Level (2024-11-05): Mitigates security vulnerabilities specific to certain hardware components, including those by Qualcomm, MediaTek, Imagination Technologies, and others.
Indicators of Compromise
Unauthorised access to directories such as “Android/data,” “Android/obb,” and “Android/sandbox.” Evidence of memory corruption where applications may throw unexpected errors or behave erratically. Some files may become corrupted, especially those that were recently accessed or modified, or frequent and unexplained crashes or reboots.
Threat Landscape
Google Android dominates the global smartphone market at 72%, significantly outstripping its main competitor, Apple’s iOS. While there are few users of the Google Pixel (2-3%) within the UK, these vulnerabilities in the Android system are critical due to it being actively exploited in the wild, posing immediate risks to affected devices. There is a possibility that these vulnerabilities could be used together in an exploit chain to elevate privileges and achieve code execution.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
TTPs
- TA0029 – Privilege Escalation
Further Information
https://source.android.com/docs/security/bulletin/2024-11-01
https://thehackernews.com/2024/11/google-warns-of-actively-exploited-cve.html













