Zimperium zLabs is Raising the Volume: New Vulnerability Processing MP3/MP4 Media.
ID: f015413a-93b0-539b-82f3-1ab9d850cff4
STIX ID: report--f015413a-93b0-539b-82f3-1ab9d850cff4
Feed Name: Zimperium Blog
Zimperium disclosed "Stagefright 2.0", two vulnerabilities in Android media libraries that permit remote code execution when specially crafted MP3/MP4 metadata is processed; CVE-2015-6602 was assigned to the libutils issue while a second CVE for libstagefright was pending. The report explains impact (RCE on Android 5.0+ and potential broader impact via third-party apps), likely attack vectors (malicious websites, MITM of unencrypted traffic, or vulnerable apps), and remediation steps including notifying Google, updating detection tools, and coordinating fixes with vendors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
