New Android Vulnerability Affects Wide Range of Devices; Google Publishes Fix

Advertisement
By Manish Singh | Updated: 19 August 2015 15:24 IST

Another day, another Android vulnerability. A new security flaw has been found in the mediaserver component of Google's mobile operating system, the same component that gave rise to the Stagefright bug. The vulnerability in question lies in the way Android handles media files, and if exploited, could allow an attacker to execute arbitrary codes. The vulnerability affects the vast majority of Android devices, running on version 2.3 to 5.1.1. Google has already published a fix for it to the AOSP program, though due to heavy fragmentation in the ecosystem, it could take a while before hitting your device.

Called CVE-2015-3842, the vulnerability has been found in the AudioEffect component of Android's mediaserver component. The vulnerability, as reported by security firm TrendMicro, lies in the implementation of this feature which does not properly check for buffer sizes supplied by clients. An attacker can abuse this vulnerability by convincing users to install apps that don't require any special permissions, and afterwards run arbitiary code on their devices.

Advertisement

"It uses an unchecked variable which comes from the client, which is usually an app. For an attack to begin, attackers convince the victim to install an app that doesn't require any required permissions, giving them a false sense of security," wrote Trend Micro in a blog post.

Among the things that could happen in the aftermath of the attack include compromised control of the camera, improper rendering of mp4 files, tweaks in privacy settings - essentially the tasks that are linked to the mediaserver component.

Advertisement

The comforting part of the news is that there are no known active exploits based on this vulnerability - and Google has already published a fix for it. Though, when will you receive this update on your device depends on the OEM. Trend Micro claims users can download its mobile security suite TMSS to be able to detect any threats trying to use the vulnerability.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Android, Google, Security, Vulnerability
Advertisement

Related Stories

Popular Mobile Brands
  1. How Instagram's Edits App Evolved Over the Past Year and What's Next
  2. NASA's Curiosity Rover Finds Crater Filled With Sand, Alters Drilling Plans
  3. Motorola Edge 70 Pro vs OnePlus Nord 6 vs Redmi Note 15 Pro+ Compared
  1. NASA’s Curiosity Rover Finds Crater Filled With Sand, Alters Drilling Plans
  2. Control Ultimate Edition Arrives on iPhone and iPad With Touch Controls, Universal Purchase
  3. Asus ExpertBook Ultra With Intel Core Ultra X7 Series 3 CPU Launched in India Alongside ExpertBook P3, ExpertBook P5 Series
  4. Boat Aavante Prime X Soundbar Launched in India With Dolby Atmos, Wireless Satellite Speakers: Price, Features
  5. Qualcomm CEO Reportedly Visits Samsung Foundry in Korea to Discuss Producing 2nm Chips
  6. Coinbase Announces USDC-INR Trading Services for Users in India
  7. Redmi K Pad 2 Launched With 8.8-Inch 3K Display, Dimensity 9500 Chip: Price, Specifications
  8. Suyodhana OTT Release Date: When and Where to Watch This Telugu Mystry Thriller Online?
  9. OnePlus Watch 4 Launch Appears Imminent as Listing Confirms Snapdragon W5 Chip, OxygenOS Watch 8
  10. Sennheiser CX 80U, Sennheiser HD 400U With USB Type-C Connectivity Launched in India: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.