IBM security researchers have found a way to exploit an Android flaw that puts more than 55% of Android phones at risk of being taken over by persistent attackers. The flaw exists in Android versions 4.3-5.1 (Jelly Bean, Kitkat and Lollipop) and a patch is available, but it is up to phone service providers to decide when and if to deploy it. The researchers presented a paper on the flaw at USENIX WOOT ’15 in Washington, D.C., in which they describe an exploit, but dont reveal the code to carry it out.”]
Source: https://www.csoonline.com/article/2968433/ibm-finds-another-android-phone-bug.html

