As far as we can tell, no Galaxy device has yet received the December 2024 security patch. However, Samsung appears to be gearing up for the event, as it recently confirmed the December update's changelog through its monthly security bulletin.
As usual, Samsung's latest release includes security fixes from both Google and Samsung. And this month, the update also includes a couple of fixes from Samsung Semiconductor.
On Google's side, the December 2024 security update contains fixes for critical and high vulnerabilities, but none for moderate-level ones.
Critical
- CVE-2024-38408, CVE-2024-43096, CVE-2024-43770, CVE-2024-43771, CVE-2024-49747, CVE-2024-49748
High
- CVE-2024-34747, CVE-2024-40671, CVE-2024-34729, CVE-2024-31337, CVE-2023-35659, CVE-2023-35686, CVE-2024-23715, CVE-2024-36978, CVE-2024-46740, CVE-2024-20106, CVE-2024-20104, CVE-2024-23385, CVE-2024-38403, CVE-2024-38424, CVE-2024-38415, CVE-2024-38423, CVE-2024-38421, CVE-2024-21455, CVE-2024-43047, CVE-2024-38405, CVE-2024-43762, CVE-2024-43764, CVE-2024-43769, CVE-2024-43767, CVE-2024-43097, CVE-2024-43768, CVE-2024-43766, CVE-2024-43763
Already included in previous updates
- CVE-2024-38402
On Samsung Mobile's side of the equation, the December 2024 security patch includes 8 SVE (Samsung Vulnerabilities and Exposures) items, only six of which have been disclosed:
- SVE-2024-1485(CVE-2024-49410): Out-of-bounds write in libswmfextractor.so
- SVE-2024-1808(CVE-2024-49411): Path Traversal in ThemeCenter
- SVE-2024-1845(CVE-2024-49415): Out-of-bound write in libsaped.so
- SVE-2024-1885(CVE-2024-49412): Improper input validation in Settings
- SVE-2024-2044(CVE-2024-49413): Improper Verification of Cryptographic Signature in SmartSwitch
- SVE-2024-2166(CVE-2024-49414): Authentication Bypass Using an Alternate Path in Dex Mode
Last but not least, as we mentioned above, the December 2024 security patch also includes two vulnerability fixes from Samsung Semiconductor. They are labeled a high-security risk and are known as
- CVE-2024-39343
- CVE-2024-39890
Samsung hasn't released the December 2024 security patch to any Galaxy phones or tablets as of this writing, but it will likely start the OTA roll-out soon. We'll keep you posted once it does.