CVE detail
CVE-2024-49848
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- Serbian government used Cellebrite to unlock phones, install spywareHelp Net Security
Serbian police and intelligence officers used Cellebrite forensic extraction software to unlock journalists’ and activists’ phones and install previously unknown Android spyware called NoviSpy, a new Amnesty International report claims. The unlocking was made possible through exploitation of a zero-day vulnerability affecting chipsets made by Qualcomm. In early October 2024, Qualcomm fixed CVE-2024-43047, reported by Google’s Threat Analysis Group (TAG) and Amnesty International as exploited in the wild. Google followed with a fix for Android … More →
newswww.helpnetsecurity.comDec 16, 2024, 6:10 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-21437CVSS 7.8 · High
Memory corruption while processing memory map or unmap IOCTL operations simultaneously.
- CVE-2024-53023CVSS 7.8 · High
Memory corruption may occur while accessing a variable during extended back to back tests.
- CVE-2024-33035CVSS 8.4 · High
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
- CVE-2024-53030CVSS 7.8 · High
Memory corruption while processing input message passed from FE driver.
- CVE-2024-45555CVSS 8.4 · High
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive…
- CVE-2024-23354CVSS 8.4 · High
Memory corruption when the IOCTL call is interrupted by a signal.