Chipmaker Qualcomm warns of three actively exploited zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22071 | Exploited Use-After-Free in Qualcomm Snapdragon and QCA Chipset Firmware CVE-2022-22071 is a use-after-free (CWE-416) in the firmware of multiple Qualcomm Snapdragon SoCs and QCA connectivity chips, occurring when process shell memory is freed via an IOCTL munmap call while process initialization is still in progress. It is triggered locally by a low-privileged process during this initialization/memory-free sequence, so an attacker who can already run code on the device can exploit it. The result is high-impact memory corruption affecting confidentiality, integrity, and availability (CVSS 3.1: 7.8), consistent with local privilege escalation or full compromise of the affected chipset-based system. Any device built on the listed Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, or Voice & Music platforms is potentially affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-05, news reports describe Qualcomm patching three actively exploited zero-days in this disclosure, and ransomware use is unknown; EPSS is 0.5% and no public PoC is known. Do: Apply the firmware fixes published in Qualcomm's security advisory via your device OEM or OS update channel, following CISA's KEV required action (patch per vendor instructions or discontinue use). Inventory devices using the listed chipsets (MSM8953/APQ8053, AR8031/AR8035, CSRA6620/CSRA6640, MDM9150, QCA6174A/6390/6391/6426/6436) and prioritize those where untrusted or low-privileged users can run code locally. Because the flaw is local-only, mitigate interim risk by restricting local code execution on affected devices; no public PoC or specific patched firmware version is available in the source data. | 7.8 | <1% | KEV |
| massHundreds of millions of devices plausibly affected (chipsets deployed across smartphone, IoT, automotive, and embedded product lines) | |
| CVE-2023-33028 +1 in the same advisory: …24855 | Memory corruption in WLAN Firmware while doing a memory copy of pmk cache. Memory corruption in WLAN Firmware while doing a memory copy of pmk cache. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-28540 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. Cryptographic issue in Data Modem due to improper authentication during TLS handshake. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-33106 | Out-of-Range Pointer Memory Corruption in Qualcomm KGSL GPU Driver (Actively Exploited) CVE-2023-33106 is a memory-corruption flaw (use of out-of-range pointer offset, CWE-823/CWE-119) in Qualcomm's KGSL GPU kernel driver, which manages the Adreno graphics stack. It is triggered when a local, low-privileged process submits an AUX command containing a large list of sync points through the IOCTL_KGSL_GPU_AUX_COMMAND ioctl, causing out-of-bounds memory access. A successful attacker, typically a malicious app already running on the device, can corrupt kernel memory and escalate privileges, gaining the high confidentiality, integrity and availability impact reflected in its CVSS 7.8 local-attack score. Affected products include the listed Qualcomm components (FastConnect 6200/6700/6800/6900/7800, QAM8255P/QAM8295P/QAM8650P, Flight RB5 5G Platform, AR8035, CSRA6620/CSRA6640), and the vendor's advisory describes the flaw as spanning multiple chipsets. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-12-05, and public reporting indicates it was one of three Qualcomm zero-days actively exploited in targeted Android attacks alongside Adreno GPU issues; no public PoC is known. Do: Install Android security updates or firmware from your device/OEM vendor that incorporate Qualcomm's fixes for this CVE, prioritizing devices and systems built on the listed chipsets, and check the Qualcomm security bulletin for the fixed firmware versions for each component. Because exploitation requires local code execution, avoid installing untrusted apps on unpatched devices as an interim mitigation. Organizations subject to BOD 22-01 must apply the vendor remediations per the KEV required action. | 7.8 | <1% | KEV |
| mass~hundreds of millions of devices (Qualcomm silicon across Android phones, automotive and IoT platforms); exact count unknown |
Full article401 words · extracted from securityaffairs.com · click to collapse

Chipmaker Qualcomm addressed 17 vulnerabilities in various components and warns of three other actively exploited zero-day flaws.
Chipmaker Qualcomm released security updates to address 17 vulnerabilities in several components.
Three out of 17 flaws are rated Critical, 13 are rated High, and one is rated Medium in severity.
The company is also warning that three other zero-day vulnerabilities are actively exploited in attacks in the wild. Google Threat Analysis Group and Google Project Zero first reported that the CVE-2023-33106, CVE-2023-33107, CVE-2022-22071 and CVE-2023-33063 are actively exploited in targeted attacks.
The company plans to disclose the technical details of the actively exploited vulnerabilities in the forthcoming months.
Google Threat Analysis Group and Google Project Zero experts focus on attacks carried out by nation-state actors or surveillance firms, this means that one of these threat actors may be behind the exploitation of the Qualcomm flaws.
“There are indications from Google Threat Analysis Group and Google Project Zero that CVE-2023-33106, CVE-2023-33107, CVE-2022-22071 and CVE-2023-33063 may be under limited, targeted exploitation. Patches for the issues affecting Adreno GPU and Compute DSP drivers have been made available, and OEMs have been notified with a strong recommendation to deploy security updates as soon as possible. Please contact your device manufacturer for more information on the patch status about specific devices.” reads the advisory. “CVE-2022-22071 was included in our May 2022 public bulletin. The details of the remaining CVEs will be shared in our December 2023 public bulletin.”
The three critical issues fixed by the chipmaker are:
| Public ID | Security Rating | CVSS Rating | Technology Area | Date Reported |
|---|---|---|---|---|
| CVE-2023-24855 | Critical | Critical (CVSS Score 9.8) | Modem | Internal |
| CVE-2023-28540 | Critical | Critical (CVSS Score 9.1) | Data Modem | Internal |
| CVE-2023-33028 | Critical | Critical (CVSS Score 9.8) | WLAN Firmware | Internal |
- CVE-2023-24855: Use of Out-of-range Pointer Offset in Modem. The issue is a memory corruption in Modem while processing security related configuration before AS Security Exchange.
- CVE-2023-28540: Improper Authentication in Data Modem. The flaw is a cryptographic issue in the Data Modem caused by the improper authentication during TLS handshake.
- CVE-2023-33028: Buffer Copy without Checking Size of Input in WLAN Firmware. The flaw is a memory corruption in WLAN Firmware that occurs while doing a memory copy of pmk cache.
There is no evidence that the above flaws have been exploited in attacks in the wild.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Qualcomm)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/151934/security/qualcomm-critical-flaws.html