CVE-2015-3827 is a critical vulnerability affecting Android versions before 5.1.1 LMY48I, residing in the MPEG4Extractor function of libstagefright. It allows remote attackers to execute arbitrary code or cause a denial of service through integer underflow and memory corruption by crafting malicious MPEG-4 covr atoms. With a CVSS score of 9.3, this vulnerability is highly severe, requiring medium attack complexity but leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its high EPSS score and significant community discussion, including media coverage of exploit releases, indicate a high likelihood of exploitation, despite no public Metasploit or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.