Final up to date: December third, 2024 at 13:23 UTC+01:00
So far as we are able to inform, no Galaxy system has but obtained the December 2024 safety patch. Nevertheless, Samsung seems to be gearing up for the occasion, because it lately confirmed the December replace’s changelog by means of its month-to-month safety bulletin.
As normal, Samsung’s newest launch contains safety fixes from each Google and Samsung. And this month, the replace additionally contains a few fixes from Samsung Semiconductor.
On Google’s aspect, the December 2024 safety replace accommodates fixes for important and excessive vulnerabilities, however none for moderate-level ones.
Vital
- CVE-2024-38408, CVE-2024-43096, CVE-2024-43770, CVE-2024-43771, CVE-2024-49747, CVE-2024-49748
Excessive
- CVE-2024-34747, CVE-2024-40671, CVE-2024-34729, CVE-2024-31337, CVE-2023-35659, CVE-2023-35686, CVE-2024-23715, CVE-2024-36978, CVE-2024-46740, CVE-2024-20106, CVE-2024-20104, CVE-2024-23385, CVE-2024-38403, CVE-2024-38424, CVE-2024-38415, CVE-2024-38423, CVE-2024-38421, CVE-2024-21455, CVE-2024-43047, CVE-2024-38405, CVE-2024-43762, CVE-2024-43764, CVE-2024-43769, CVE-2024-43767, CVE-2024-43097, CVE-2024-43768, CVE-2024-43766, CVE-2024-43763
Already included in earlier updates
On Samsung Cell’s aspect of the equation, the December 2024 safety patch contains 8 SVE (Samsung Vulnerabilities and Exposures) objects, solely six of which have been disclosed:
- SVE-2024-1485(CVE-2024-49410): Out-of-bounds write in libswmfextractor.so
- SVE-2024-1808(CVE-2024-49411): Path Traversal in ThemeCenter
- SVE-2024-1845(CVE-2024-49415): Out-of-bound write in libsaped.so
- SVE-2024-1885(CVE-2024-49412): Improper enter validation in Settings
- SVE-2024-2044(CVE-2024-49413): Improper Verification of Cryptographic Signature in SmartSwitch
- SVE-2024-2166(CVE-2024-49414): Authentication Bypass Utilizing an Alternate Path in Dex Mode
Final however not least, as we talked about above, the December 2024 safety patch additionally contains two vulnerability fixes from Samsung Semiconductor. They’re labeled a high-security danger and are referred to as
- CVE-2024-39343
- CVE-2024-39890
Samsung hasn’t launched the December 2024 safety patch to any Galaxy telephones or tablets as of this writing, however it’s going to seemingly begin the OTA roll-out quickly. We’ll preserve you posted as soon as it does.