← Vulnerability feed

Vulnerability record · CVE-2015-1539 · published 1 October 2015

CVE-2015-1539: Android libstagefright ESDS integer underflow allows remote code execution

Google · Android

Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in Android's libstagefright allow remote attackers to execute arbitrary code via crafted ESDS atoms. The flaw affects Android before 5.1.1 LMY48I and is a related issue to CVE-2015-4493. Because libstagefright processes media, a malformed media file can trigger memory corruption on an unpatched device.

10.0 CVSS 2.0 High EPSS 86% · top 0.3% CWE-189 · CWE-189
10.0CVSS 2.0 base score
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via crafted ESDS atoms, aka internal bug 20139950, a related issue to CVE-2015-4493.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 2.0 base score is 10 with network reachability and no authentication, and EPSS is 0.85792 at the 99.7th percentile, though the record lacks KEV listing and confirmed public exploit code.

What it is

Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in Android's libstagefright allow remote attackers to execute arbitrary code via crafted ESDS atoms. The flaw affects Android before 5.1.1 LMY48I and is a related issue to CVE-2015-4493. Because libstagefright processes media, a malformed media file can trigger memory corruption on an unpatched device.

Impact

An attacker can execute arbitrary code in the context of the affected media processing component, giving full compromise of confidentiality, integrity and availability per the CVSS 2.0 vector. No user privileges are required beyond the device processing the crafted media.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and low complexity. In practice this means a crafted ESDS atom delivered through media handling, typically requiring the victim to open or play the malicious media.

Exploitation

CVE-2015-1539 is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is very high at 0.85792 (percentile 0.99715), indicating strong predicted exploitation activity. Reference tags are limited to Vendor Advisory, so no public exploit code is confirmed by the record.

What to do

  • Apply the Android 5.1.1 LMY48I or later update, or the vendor patch referenced in the Android source commit 5e751957ba692658b7f67eb03ae5ddb2cd3d970c.
  • For devices that cannot be updated, restrict or disable untrusted media playback and avoid opening media from unknown sources.
  • Track vendor advisories (Google Android security updates, Huawei HW-448928) for backported fixes on affected OEM builds.
  • Where feasible, enforce memory-safe media parsing or sandboxing for the media framework to reduce the impact of a successful exploit.

Detection

  • Monitor for crashes or abnormal terminations in libstagefright or the media server process when processing ESDS atoms.
  • Inspect media files for malformed or oversized ESDS atom structures before they reach the media parser.
  • Correlate endpoint telemetry for code execution or memory corruption events originating from media playback on unpatched Android builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-1539 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-58704Android Cellular Modem improper authorization allows adjacent privilege escalationAndroid's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escala…KEVEPSS 0.59%analysed8.8CVE-2025-48543Android use-after-free allows Chrome sandbox escape to system_serverA use-after-free in multiple Android locations lets an attacker escape the Chrome sandbox and reach the Android system_server process. Because the fl…KEVEPSS 0.54%analysed8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2025-48572Android Framework permissions bypass enables background activity launchMultiple locations in the Android Framework allow activities to be launched from the background because of a permissions bypass, a missing authentica…KEVEPSS 0.26%analysed7.8CVE-2024-32896Android Pixel logic error allows local privilege escalationCVE-2024-32896 is a logic error in Android (CWE-670/CWE-783) that permits a local attacker to bypass intended restrictions and escalate privileges. I…KEVEPSS 3.0%analysed7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed7.8CVE-2023-35674Android WindowState logic error allows background activity launch and privilege escalationA logic error in onCreate of WindowState.java in the Android Framework lets a background activity be launched, enabling local escalation of privilege…KEVEPSS 2.6%analysed7.8CVE-2023-20963Android WorkSource parcel mismatch local privilege escalationCVE-2023-20963 is a parcel mismatch in Android's WorkSource component that allows a local attacker to escalate privileges without additional executio…KEVEPSS 1.5%analysed

Source: NIST National Vulnerability Database (record CVE-2015-1539), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.