CVE-2015-6612 describes a privilege escalation vulnerability in the libmedia component of Android, affecting versions before 5.1.1 LMY48X and 6.0 before the November 2015 security update. This critical vulnerability, with a CVSS score of 9.3, allows an unauthenticated attacker to gain full control over an affected device through a crafted application, requiring moderate attack complexity. While no public exploit code or active exploitation is reported, the vulnerability garnered some community and media attention at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0, < 5.1.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.