Vulnerability record · CVE-2015-1539 · published 1 October 2015
CVE-2015-1539: Android libstagefright ESDS integer underflow allows remote code execution
Google · Android
Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in Android's libstagefright allow remote attackers to execute arbitrary code via crafted ESDS atoms. The flaw affects Android before 5.1.1 LMY48I and is a related issue to CVE-2015-4493. Because libstagefright processes media, a malformed media file can trigger memory corruption on an unpatched device.
Description
Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via crafted ESDS atoms, aka internal bug 20139950, a related issue to CVE-2015-4493.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 2.0 base score is 10 with network reachability and no authentication, and EPSS is 0.85792 at the 99.7th percentile, though the record lacks KEV listing and confirmed public exploit code.
What it is
Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in Android's libstagefright allow remote attackers to execute arbitrary code via crafted ESDS atoms. The flaw affects Android before 5.1.1 LMY48I and is a related issue to CVE-2015-4493. Because libstagefright processes media, a malformed media file can trigger memory corruption on an unpatched device.
Impact
An attacker can execute arbitrary code in the context of the affected media processing component, giving full compromise of confidentiality, integrity and availability per the CVSS 2.0 vector. No user privileges are required beyond the device processing the crafted media.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and low complexity. In practice this means a crafted ESDS atom delivered through media handling, typically requiring the victim to open or play the malicious media.
Exploitation
CVE-2015-1539 is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is very high at 0.85792 (percentile 0.99715), indicating strong predicted exploitation activity. Reference tags are limited to Vendor Advisory, so no public exploit code is confirmed by the record.
What to do
- Apply the Android 5.1.1 LMY48I or later update, or the vendor patch referenced in the Android source commit 5e751957ba692658b7f67eb03ae5ddb2cd3d970c.
- For devices that cannot be updated, restrict or disable untrusted media playback and avoid opening media from unknown sources.
- Track vendor advisories (Google Android security updates, Huawei HW-448928) for backported fixes on affected OEM builds.
- Where feasible, enforce memory-safe media parsing or sandboxing for the media framework to reduce the impact of a successful exploit.
Detection
- Monitor for crashes or abnormal terminations in libstagefright or the media server process when processing ESDS atoms.
- Inspect media files for malformed or oversized ESDS atom structures before they reach the media parser.
- Correlate endpoint telemetry for code execution or memory corruption events originating from media playback on unpatched Android builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-1539 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1539), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.