A vulnerability in the multimedia library libstagefright.so in Android allows for remote code execution on the device via MMS.
Stagefright is a vulnerability utilizing several bugs in the libstagefright.so library. These bugs are reported as CVEs, and can be found here:
The vulnerability works by crafting a malicious video file, and texting it to the victim. The victim's Android device will then try to preprocess that video file when received. A weakness in this processing routine enables the video file to execute malicious code. (Major Flaw In Android Phones Would Let Hackers In With Just A Text)