
Google has patched seven of its code execution vulnerabilities, two of which were rated critical, four high, and one moderate. This was the fourth round of Android patching since August of this year.
Two flaws, which allow attackers to perform remote code execution, and were rated 'critical' include the libutils (CVE-2015-6609) and mediaserver (CVE-2015-6608) holes. These holes can be exploited by sending crafted media files to affected devices.
Google notified its partners about the patch on October 5, and while the patch code is available for Nexus, Samsung, and the Android Open Source Project, it will be announced for the latest Marshmallow Android operating system.
In its advisory, Google states, “Most important of all is the critical security vulnerability that could allow remote code execution on an affected device via multiple methods including email, web browsing, and MMS when containing media files.”
The privilege elevation bug was resolved in the libstagefright library, which was separate from the StageFright vulnerabilities reported by researcher Joshua Drake earlier this year.
Vulnerabilities in Bluetooth (CVE-2015-6613), mediaserver (CVE-2015-6611), and telephone app (CVE-2015-6614), as well as libmedia (CVE-2015-6612) were also fixed.
Google indicatively states that "Exploiting vulnerabilities is becoming increasingly difficult on the security Marshmallow Android platform."

