New Android Vulnerability Affects Wide Range of Devices; Google Publishes Fix

Advertisement
By Manish Singh | Updated: 19 August 2015 15:24 IST

Another day, another Android vulnerability. A new security flaw has been found in the mediaserver component of Google's mobile operating system, the same component that gave rise to the Stagefright bug. The vulnerability in question lies in the way Android handles media files, and if exploited, could allow an attacker to execute arbitrary codes. The vulnerability affects the vast majority of Android devices, running on version 2.3 to 5.1.1. Google has already published a fix for it to the AOSP program, though due to heavy fragmentation in the ecosystem, it could take a while before hitting your device.

Called CVE-2015-3842, the vulnerability has been found in the AudioEffect component of Android's mediaserver component. The vulnerability, as reported by security firm TrendMicro, lies in the implementation of this feature which does not properly check for buffer sizes supplied by clients. An attacker can abuse this vulnerability by convincing users to install apps that don't require any special permissions, and afterwards run arbitiary code on their devices.

"It uses an unchecked variable which comes from the client, which is usually an app. For an attack to begin, attackers convince the victim to install an app that doesn't require any required permissions, giving them a false sense of security," wrote Trend Micro in a blog post.

Advertisement

Among the things that could happen in the aftermath of the attack include compromised control of the camera, improper rendering of mp4 files, tweaks in privacy settings - essentially the tasks that are linked to the mediaserver component.

The comforting part of the news is that there are no known active exploits based on this vulnerability - and Google has already published a fix for it. Though, when will you receive this update on your device depends on the OEM. Trend Micro claims users can download its mobile security suite TMSS to be able to detect any threats trying to use the vulnerability.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Further reading: Android, Google, Security, Vulnerability
Advertisement

Related Stories

Popular Mobile Brands
  1. Arc Raiders Will Get Multiple New Maps This Year, Says Embark
  2. Samsung Galaxy S26 Ultra Colourways Spotted in Leaked SIM Tray Images
  3. Oakley Meta HSTN Smart Glasses Review
  4. How To Delete Instagram Account | Step-By-Step Guide
  5. Here's How Much the Realme P4 Power Could Cost in India
  1. Global RAM Shortage Is Reportedly Causing GPU, Storage Drive Prices to Skyrocket
  2. Viruses and Bacteria Evolve Differently in Space, ISS Study Finds
  3. Rockstar Games Said to Have Granted a Terminally Ill Fan's Wish to Play GTA 6
  4. Oppo K15 Turbo Series Tipped to Feature Built-in Cooling Fans; Oppo K15 Pro Model Said to Get MediaTek Chipset
  5. Samsung Galaxy Z Fold 8 Said to Feature Dual Ultra-Thin Glass OLED Panel to Reduce Crease Visibility
  6. Honor Magic 8 Pro Air Launched Alongside Honor Magic 8 RSR Porsche Design: Price, Specifications
  7. Realme Neo 8 Key Specifications Including 8,000mAh Battery, Ultrasonic Fingerprint Sensor Confirmed
  8. Astronomers Find Massive Iron-Rich Feature Lurking Under the Ring Nebula
  9. Asus Reportedly Halts Smartphone Launches ‘Temporarily’ to Focus on AI Robots, Smart Glasses
  10. JioHotstar Announces Monthly Subscription Plans Across Mobile, Super, and Premium Tiers
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.