Qualcomm has just confirmed a zero-day vulnerability (CVE-2024-43047) affecting 64 of its chipsets, including the Snapdragon 8 Gen 1, Snapdragon 888, widely used in popular Android devices.

This vulnerability was discovered by Google Threat Analysis Group (TAG) and Amnesty International's Security Lab and has limited potential for exploitation for specific targets.
Qualcomm said it has released a patch to device manufacturers (OEMs) in September 2024, and recommends users update immediately. However, details of the attacks and targets have not been disclosed.
The list of affected chipsets includes many popular mobile platforms, affecting millions of Android device users.
List of Qualcomm chipsets affected by zero-day vulnerability CVE-2024-43047:
- SD660
- SD865 5G
- SG4150P
- Snapdragon 660 Mobile Platform
- Snapdragon 680 4G Mobile Platform
- Snapdragon 685 4G Mobile Platform (SM6225-AD)
- Snapdragon 8 Gen 1 Mobile Platform
- Snapdragon 865 5G Mobile Platform
- Snapdragon 865+ 5G Mobile Platform (SM8250-AB)
- Snapdragon 870 5G Mobile Platform (SM8250-AC)
- Snapdragon 888 5G Mobile Platform
- Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
Connect
- FastConnect 6700
- FastConnect 6800
- FastConnect 6900
- FastConnect 7800
Sound
- QAM8295P
- SA4150P
- SA4155P
- SA6145P
- SA6150P
- SA6155P
- SA8145P
- SA8150P
- SA8155P
- SA8195P
- SA8295P
- WCD9335
- WCD9341
- WCD9370
- WCD9375
- WCD9380
- WCD9385
Connect
- QCA6174A
- QCA6391
- QCA6426
- QCA6436
- QCA6574AU
- QCA6584AU
- QCA6595
- QCA6595AU
- QCA6688AQ
- QCA6696
- QCA6698AQ
- WCN3950
- WCN3980
- WCN3988
- WCN3990
- WSA8810
- WSA8815
- WSA8830
- WSA8835
Modem-RF
- Snapdragon Auto 5G Modem-RF
- Snapdragon Auto 5G Modem-RF Gen 2
- Snapdragon X55 5G Modem-RF System
Other platforms
- QCS410
- QCS610
- QCS6490
- Qualcomm® Video Collaboration VC1 Platform
- Qualcomm® Video Collaboration VC3 Platform
- Snapdragon XR2 5G Platform
- SW5100
- SW5100P
- SXR2130