Blog
Zero-Day Deserialization Vulnerability Affects 55% of Android Devices
By David Bisson on Tue, 08/11/2015
Security researchers have uncovered a zero-day deserialization vulnerability that allows for arbitrary code execution in 55% of Android devices. For their presentation at USENIX WOOT '15, researchers Or Peles and Roee Hay at IBM Security explain that their vulnerability (CVE-2015-3825) can be exploited in the context of many apps and can be used to...