CVE-2023-33063
KEVmass1Use-After-Free in Qualcomm DSP Services Across Multiple Chipsets
CISA: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
CVE-2023-33063 is a use-after-free (CWE-416) memory corruption flaw in Qualcomm's DSP Services, triggered during a remote call from the high-level OS (HLOS, e.g., Android) to the digital signal processor. A local attacker with limited privileges (no user interaction required) can trigger the flaw to corrupt memory, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, local attack vector). It affects firmware across a wide range of Qualcomm silicon, including the 315 5G IoT Modem, APQ8017, AQT1000, AR8031/AR8035, AR9380, C-V2X 9150, CSR8811, CSRA6620/CSRA6640, CSRB31024, and WCN3991. The vulnerability is confirmed exploited in the wild — it was added to the CISA Known Exploited Vulnerabilities catalog on 2023-12-05, and press coverage links the disclosure to three actively exploited Qualcomm zero-days used in targeted Android attacks. EPSS is modest (0.7% probability of exploitation in 30 days), but KEV inclusion indicates real-world exploitation in targeted attacks.
What to do: Apply the remediations from Qualcomm's security bulletin for CVE-2023-33063, and because these are embedded firmware components, coordinate with device/OEM and module vendors to obtain and install updated firmware as it becomes available. Defenders should prioritize this per CISA KEV (added 2023-12-05), inventory devices using the affected Qualcomm chipsets, and as an interim mitigation limit untrusted app installation on affected Android endpoints, since exploitation requires local code execution from the OS side.
| Qualcomm 315 5G IoT Modem | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm APQ8017 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm AQT1000 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm AR8031 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm AR8035 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm AR9380 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm C-V2X 9150 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm CSR8811 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm CSRA6620 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm CSRA6640 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm CSRB31024 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
| Qualcomm WCN3991 | firmware; no specific version ranges provided in source data (see Qualcomm security bulletin) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory corruption in DSP Services during a remote call from HLOS to DSP.
- Affected
- Qualcomm Multiple Chipsets
- Required action
- Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualcomm
- Products
- 315 5g iot modem firmware, apq8017 firmware, aqt1000 firmware, ar8031 firmware, ar8035 firmware, ar9380 firmware, c-v2x 9150 firmware, csr8811 firmware, csra6620 firmware, csra6640 firmware, csrb31024 firmware, wcn3991 firmware
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H