Skip to main content

Issues on Android "Stagefright" Media Library Remote Code Execution Vulnerabilities

Release Date: 28 Jul 2015 1932 Views

Recently, a security research company reported that remote code execution vulnerabilities were identified in Android smartphones. With these vulnerabilities, arbitrary code would be executed upon MMS message received on target smartphone.



  • ZIMPERIUM security research company [1] reported that remote code execution vulnerabilities were identified in Android media library "Stagefright".
  • The vulnerabilities affected Android 2.2 or later.
  • When the crafted MMS is received by the phone, arbitrary code could be executed without any user interaction.
  • Vendor patch is currently unavailable.

HKCERT has issued a security bulletin for the said vulnerabilities. Please refer to it for workaround solutions:



[1] Reference: