Security Flaws in Qualcomm’s Adreno GPUs Impact Millions of Android Phones

Researchers at Google have uncovered significant security flaws in Qualcomm’s Adreno GPU, which could impact billions of Android devices worldwide. If these vulnerabilities are exploited, they could allow unauthorized access and control over devices, posing severe risks to user data and privacy.

Qualcomm, a prominent producer of mobile processors and wireless technologies, has acknowledged these vulnerabilities in its latest security update. The company is collaborating with Android device manufacturers to create and implement essential patches to address these issues.

Overview of Qualcomm Adreno GPU Vulnerabilities

The security issues are primarily linked to Qualcomm’s proprietary Adreno GPU software. These flaws have been classified as high-risk, with several being rated as critical.

The vulnerabilities affect several technology components, including the Multi-Mode Call Processor, Hypervisor, and High-Level Operating System (HLOS).

These security weaknesses impact a wide range of Android devices from major brands such as Samsung, Google, Xiaomi, OnePlus, and others using Qualcomm’s Adreno GPU.

Qualcomm’s security bulletin lists the affected chipsets and advises device manufacturers to quickly incorporate the provided patches into their firmware updates.

The vulnerabilities are due to inadequate memory management in the Adreno GPU driver, potentially leading to memory corruption, data leaks, and arbitrary code execution. Malicious apps or compromised websites could exploit these issues to gain elevated privileges on affected devices.

High-Severity Vulnerabilities

  • CVE-2024-23350: A critical issue in the Multi-Mode Call Processor that may cause a Denial of Service (DoS) attack when multiple payloads are processed, including a Security of Radio (SOR) container with a failed integrity check.
  • CVE-2024-21481: A severe flaw in the Hypervisor that results in memory corruption during shared memory notification setup, allowing attackers to execute arbitrary code on the device.
  • CVE-2024-23352: Another critical vulnerability in the Multi-Mode Call Processor that can trigger an infinite loop, leading to a temporary DoS condition.
  • CVE-2024-23353: Involves a buffer over-read in the Multi-Mode Call Processor, potentially causing a transient DoS when decoding specific network messages.

Additionally, researchers have discovered a buffer over-read flaw in Qualcomm’s audio processing component.

  • CVE-2024-21479: This issue can lead to a temporary DoS during the playback of ALAC audio content. While less severe than the GPU vulnerabilities, it still affects device stability and reliability.

Impact and Actions

The vulnerabilities affect a range of Qualcomm chipsets, including the Snapdragon 8 Gen 3 Mobile Platform and various 5G Modem-RF Systems.

Given the widespread use of Qualcomm chipsets in Android devices, the potential impact is substantial, with billions of users potentially affected globally.

Qualcomm is actively addressing these vulnerabilities and working with Original Equipment Manufacturers (OEMs) to distribute the necessary patches. Users should update their devices as soon as patches become available to minimize potential risks.

The company has expressed appreciation to the researchers who identified these issues and is coordinating with industry partners and the Google Android Security team to ensure prompt updates.

This situation highlights the critical need for robust security measures in software development and ongoing vigilance within the tech industry.

Users are advised to stay informed about security updates and take steps to safeguard their devices.

More Articles & Posts