Summary
Google has released November security updates to address 40 vulnerabilities affecting the Android operating system.
Note: The vendor states that CVE-2024-43047 and CVE-2024-43093 are being actively exploited online.
Risk
Vulnerability impact estimate on the reference community: SEVERE/RED (76.66/100)1.
Type
- Elevation of Privilege
- Denial of Service
- Remote Code Execution
- Information Disclosure
Affected products and versions
Android 12, 12L, 13, 14, 15 with security patches prior to November 2024.
Mitigation actions
In line with the vendor’s statements, it is recommended to apply the patches following the indications reported in the security bulletin, available in the References section.
Unique Vulnerability Identifiers
References
https://source.android.com/docs/security/bulletin/2024-11-01
1This estimate is made taking into account several parameters, including: CVSS, availability of patches/workarounds and PoC, diffusion of the affected software/devices in the reference community.