Junglewise Threat Intelligence

CVE-2023-33063: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

CVE-2023-33063 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-12-05

Technologies: Qualcomm Multiple Chipsets. Vendors: Qualcomm.

Executive brief

A use-after-free vulnerability exists in Qualcomm chipsets due to memory corruption in DSP Services. This occurs during a remote call from the High-Level Operating System (HLOS) to the Digital Signal Processor (DSP).

Affected products

  • Qualcomm 315 5G IoT Modem Firmware -
  • Qualcomm APQ8017 Firmware -

Timeline

  • 2023-12-05: disclosed
  • 2023-12-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-12-05: patched: Qualcomm released a security bulletin and patches in December 2023.
  • exploited: Reported as exploited in the wild per CISA and advisory data.

Related threats