CVE-2024-43047
KEVmassUse-After-Free in Qualcomm FastConnect and QCA Chipset Firmware
CISA: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
CVE-2024-43047 is a use-after-free vulnerability (CWE-416) in the firmware of several Qualcomm connectivity chipsets and the QAM8295P automotive SoC, where maintaining memory maps of high-level operating system (HLOS) memory causes memory corruption. The flaw is scored with a local attack vector and low privileges required (CVSS 3.1: 7.8), so an attacker needs some local foothold, such as a malicious app on an Android device, and can then leverage the memory corruption for high-impact confidentiality, integrity, and availability effects, in practice a privilege escalation to system or kernel level. Anyone running devices built on the affected chips is exposed, including Android smartphones with FastConnect 6700/6800/6900/7800, devices using QCA-series Wi-Fi chips, and automotive platforms using the QAM8295P. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-08, and news reports describe targeted, limited Android attacks, though ransomware use is unknown and EPSS remains modest at 0.7%.
What to do: Apply Qualcomm's fix through your device or system OEM: install the latest Android security updates on affected phones, and update firmware/drivers for QCA-series Wi-Fi chips and the QAM8295P automotive SoC per vendor instructions; because this is a local firmware flaw, there is no user-side mitigation short of patching. Organizations under CISA KEV must remediate per the required action (apply vendor remediations or discontinue use). Prioritize an inventory of Android devices with FastConnect 6700/6800/6900/7800 and QCA6xxx/65xxx chips, noting this flaw is being used in targeted attacks rather than mass-scale campaigns.
| qualcomm fastconnect 6700 firmware | — |
| qualcomm fastconnect 6800 firmware | — |
| qualcomm fastconnect 6900 firmware | — |
| qualcomm fastconnect 7800 firmware | — |
| qualcomm qam8295p firmware | — |
| qualcomm qca6174a firmware | — |
| qualcomm qca6391 firmware | — |
| qualcomm qca6426 firmware | — |
| qualcomm qca6436 firmware | — |
| qualcomm qca6574au firmware | — |
| qualcomm qca6584au firmware | — |
| qualcomm qca6595 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory corruption while maintaining memory maps of HLOS memory.
- Affected
- Qualcomm Multiple Chipsets
- Required action
- Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualcomm
- Products
- fastconnect 6700 firmware, fastconnect 6800 firmware, fastconnect 6900 firmware, fastconnect 7800 firmware, qam8295p firmware, qca6174a firmware, qca6391 firmware, qca6426 firmware, qca6436 firmware, qca6574au firmware, qca6584au firmware, qca6595 firmware
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H