A privilege escalation vulnerability exists in libstagefright in Android versions prior to 5.1.1 LMY48Z and 6.0 before the 2015-12-01 security patch. Attackers can exploit this vulnerability via a crafted application to gain elevated privileges, specifically obtaining Signature or SignatureOrSystem access. This is related to internal bugs 24123723 and 24445127.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) exploit for CVE-2015-6620, a vulnerability in the Android mediaserver component (specifically, the AMessage::FromParcel deserialization logic). The repository contains four files: a .gitignore, a LICENSE, a README.md with detailed vulnerability and exploitation explanation, and the main exploit code in main.cpp. The exploit works by creating a custom IStreamSource and leveraging the IStreamListener binder interface to send a maliciously crafted Parcel object to the mediaserver. The Parcel is constructed such that the mNumItems field in the AMessage object is set to a value exceeding the fixed array size, leading to out-of-bounds writes and potential arbitrary memory freeing. This can result in a crash (SIGSEGV) or further memory corruption, as demonstrated by the included crash logs. To use the exploit, the user compiles main.cpp to produce a binary named 'stream', pushes it to the target Android device, and runs it with a media file as input. The exploit is local in nature, requiring shell access to the device. The README provides a detailed walkthrough of the vulnerability, exploitation method, and sample crash output, making this a high-quality POC for researchers and security analysts. No network endpoints or remote services are targeted; the attack is performed locally via the Android binder IPC mechanism. The main target is the /system/bin/mediaserver process, and the exploit is specific to vulnerable Android versions prior to the patch for CVE-2015-6620.
This repository contains a proof-of-concept (POC) exploit for CVE-2015-6620, a vulnerability in the Android media framework (specifically the MediaCodec/DRM subsystem) affecting Android 5.1.1 (LMY48I, hammerhead). The repository consists of a README.md and a single C++ exploit file (poc.cpp). The exploit leverages Android's binder IPC mechanism to interact with the media player and DRM services, performing heap spraying with crafted payloads to manipulate memory and trigger either an information leak or process control (potential code execution). The exploit demonstrates the vulnerability by spraying memory with controlled data and then triggering the vulnerable code path via the DRM service. The main fingerprintable endpoint is the 'media.player' binder service. The code is a POC and requires local execution on a vulnerable device, with no remote network interaction. The exploit is not weaponized but provides a clear demonstration of the vulnerability's impact.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.