← Vulnerability feed

Vulnerability record · CVE-2015-3864 · published 1 October 2015

CVE-2015-3864: Android libstagefright MPEG4Extractor integer underflow allows remote code execution

Google · Android

An integer underflow in MPEG4Extractor::parseChunk in libstagefright's mediaserver lets a crafted MPEG-4 file trigger memory corruption. It is an incomplete fix for CVE-2015-3824, so the original patch did not fully close the parsing flaw. Because mediaserver processes media automatically, this class of bug is remotely reachable and dangerous.

10.0 CVSS 2.0 High EPSS 87% · top 0.3% CWE-189 · CWE-189
10.0CVSS 2.0 base score
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0, no authentication required, remote code execution in a core Android service, and public exploit code with very high EPSS make this a top remediation priority.

What it is

An integer underflow in MPEG4Extractor::parseChunk in libstagefright's mediaserver lets a crafted MPEG-4 file trigger memory corruption. It is an incomplete fix for CVE-2015-3824, so the original patch did not fully close the parsing flaw. Because mediaserver processes media automatically, this class of bug is remotely reachable and dangerous.

Impact

A remote attacker can execute arbitrary code in the context of the mediaserver process, which historically runs with elevated privileges on Android. That can lead to full compromise of the device's media and related system components.

Attack surface

Reached by supplying crafted MPEG-4 data to the media parsing path, for example via a file, MMS, or web content that triggers media playback. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no special access are required; user interaction is not specified in the record.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.87125, 99.74th percentile) and public exploit code exists in Exploit-DB and a Metasploit module, indicating active exploitation is feasible.

What to do

  • Patch Android to 5.1.1 LMY48M or later, or apply the vendor fix referenced in the Android source commit.
  • If patching is delayed, restrict untrusted media handling and avoid opening MPEG-4 files from unknown sources.
  • Disable or limit automatic MMS/media preview processing where feasible.
  • Track devices that cannot be updated and isolate them from sensitive data or networks.

Detection

  • Monitor for crashes or abnormal restarts of mediaserver and related media processes.
  • Hunt for exploit artifacts or known Metasploit/Exploit-DB payload patterns in media files or network traffic.
  • Review device logs for repeated media parsing failures tied to MPEG-4 content.
  • Use EDR or MDM telemetry to flag devices below Android 5.1.1 LMY48M.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-3864 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-58704Android Cellular Modem improper authorization allows adjacent privilege escalationAndroid's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escala…KEVEPSS 0.59%analysed8.8CVE-2025-48543Android use-after-free allows Chrome sandbox escape to system_serverA use-after-free in multiple Android locations lets an attacker escape the Chrome sandbox and reach the Android system_server process. Because the fl…KEVEPSS 0.54%analysed8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2025-48572Android Framework permissions bypass enables background activity launchMultiple locations in the Android Framework allow activities to be launched from the background because of a permissions bypass, a missing authentica…KEVEPSS 0.26%analysed7.8CVE-2024-32896Android Pixel logic error allows local privilege escalationCVE-2024-32896 is a logic error in Android (CWE-670/CWE-783) that permits a local attacker to bypass intended restrictions and escalate privileges. I…KEVEPSS 3.0%analysed7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed7.8CVE-2023-35674Android WindowState logic error allows background activity launch and privilege escalationA logic error in onCreate of WindowState.java in the Android Framework lets a background activity be launched, enabling local escalation of privilege…KEVEPSS 2.6%analysed7.8CVE-2023-20963Android WorkSource parcel mismatch local privilege escalationCVE-2023-20963 is a parcel mismatch in Android's WorkSource component that allows a local attacker to escalate privileges without additional executio…KEVEPSS 1.5%analysed

Source: NIST National Vulnerability Database (record CVE-2015-3864), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.