CVE-2015-2001 describes a critical vulnerability in the MetaIO SDK prior to version 6.0.2.1 for Android, allowing remote attackers to execute arbitrary code. This high-severity flaw (CVSS 9.8) stems from a finalize method in a Serializable class improperly passing an attacker-controlled pointer to a native function. While no public exploit code or active exploitation is confirmed, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential impact. Despite its age, the high FAUCET Risk Score of 80/100 suggests a significant threat if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.0.2.1CPE matchmatch criteria | cpe:2.3:a:metaio:metaio_sdk:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.