Vulnerability record · CVE-2015-3864 · published 1 October 2015
CVE-2015-3864: Android libstagefright MPEG4Extractor integer underflow allows remote code execution
Google · Android
An integer underflow in MPEG4Extractor::parseChunk in libstagefright's mediaserver lets a crafted MPEG-4 file trigger memory corruption. It is an incomplete fix for CVE-2015-3824, so the original patch did not fully close the parsing flaw. Because mediaserver processes media automatically, this class of bug is remotely reachable and dangerous.
Description
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0, no authentication required, remote code execution in a core Android service, and public exploit code with very high EPSS make this a top remediation priority.
What it is
An integer underflow in MPEG4Extractor::parseChunk in libstagefright's mediaserver lets a crafted MPEG-4 file trigger memory corruption. It is an incomplete fix for CVE-2015-3824, so the original patch did not fully close the parsing flaw. Because mediaserver processes media automatically, this class of bug is remotely reachable and dangerous.
Impact
A remote attacker can execute arbitrary code in the context of the mediaserver process, which historically runs with elevated privileges on Android. That can lead to full compromise of the device's media and related system components.
Attack surface
Reached by supplying crafted MPEG-4 data to the media parsing path, for example via a file, MMS, or web content that triggers media playback. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no special access are required; user interaction is not specified in the record.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.87125, 99.74th percentile) and public exploit code exists in Exploit-DB and a Metasploit module, indicating active exploitation is feasible.
What to do
- Patch Android to 5.1.1 LMY48M or later, or apply the vendor fix referenced in the Android source commit.
- If patching is delayed, restrict untrusted media handling and avoid opening MPEG-4 files from unknown sources.
- Disable or limit automatic MMS/media preview processing where feasible.
- Track devices that cannot be updated and isolate them from sensitive data or networks.
Detection
- Monitor for crashes or abnormal restarts of mediaserver and related media processes.
- Hunt for exploit artifacts or known Metasploit/Exploit-DB payload patterns in media files or network traffic.
- Review device logs for repeated media parsing failures tied to MPEG-4 content.
- Use EDR or MDM telemetry to flag devices below Android 5.1.1 LMY48M.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-3864 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-3864), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.