CVE-2025-21042
KEVmassOut-of-Bounds Write RCE in Samsung Mobile Image Codec (libimagecodec.quram.so)
CISA: Samsung Mobile Devices Out-of-Bounds Write Vulnerability
CVE-2025-21042 is an out-of-bounds write (CWE-787) in libimagecodec.quram.so, the Quram image codec library in the image-processing stack of Samsung mobile devices. A remote attacker can trigger the flaw by getting a vulnerable device to decode a crafted image or media file, corrupting memory and potentially executing arbitrary code (the advisory does not specify the exact delivery vector, such as messaging or web content). Successful exploitation allows the attacker to run code on the device, though whether execution is confined to the decoding application or achieves broader privileges is not stated. Any Samsung mobile device using the affected codec is potentially at risk; CISA lists the product only as 'Samsung Mobile Devices' without model or version detail. The flaw is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2025-11-10 (ransomware use unknown), no public PoC is known, and EPSS assigns a 33.2% probability of exploitation within 30 days (98th percentile).
What to do: Install the latest Samsung security maintenance release (SMR) / monthly security update on all Samsung mobile devices and verify each device's Android security patch level includes the fix for this CVE; per CISA's KEV required action, apply the vendor's mitigations, and federal civilian agencies must follow BOD 22-01 or discontinue use of affected products. Until the update is confirmed, treat untrusted image/media files (e.g., received via messaging or web) as a risk vector on Samsung devices and monitor Samsung's security advisories for the affected-model list.
| Samsung Mobile Devices | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
- Affected
- Samsung Mobile Devices
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H