MetaIO SDK
Before 6.0.2.1
Use version 6.0.2.1 or later.
The MetaIO SDK for Android contains a Serializable class, with a ‘finalize’ method that later calls a native function with an attacker-controllabe pointer, eventually allowing for code execution by malicious apps.