CVE-2015-7897
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 7.0%
from disclosure to weapon0 days
Published on NVDNov 16
1st PoCNov 3
exploitation probability
7.0%top 7% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image file.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38611cve_referencepacketstormsecurity.com/files/134199/Samsung-Galaxy-S6-Android.media.process-Face-Recognition-Memory-Corruption.htmlunverifiedcve_referencewww.exploit-db.com/exploits/38611/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://googleprojectzero.blogspot.com/2015/11/hack-galaxy-hunting-bugs-in-samsung.htmlhttp://packetstormsecurity.com/files/134199/Samsung-Galaxy-S6-Android.media.process-Face-Recognition-Memory-Corruption.htmlhttps://code.google.com/p/google-security-research/issues/detail?id=499&q=samsunghttps://www.exploit-db.com/exploits/38611/