CVE-2025-21043
KEVmass2Out-of-Bounds Write RCE in Samsung Mobile Image Codec (libimagecodec.quram.so)
CISA: Samsung Mobile Devices Out-of-Bounds Write Vulnerability
CVE-2025-21043 is an out-of-bounds write vulnerability (CWE-787) in libimagecodec.quram.so, the image-decoding library used by Samsung Mobile Devices. It can be triggered remotely when the vulnerable codec processes maliciously crafted image data, and per the CVSS vector it requires no privileges or user interaction. A successful attack allows a remote attacker to execute arbitrary code on the device with high impact on confidentiality, integrity, and availability (CVSS 9.8, critical). All Samsung mobile devices running a security update prior to the September 2025 Maintenance Release (SMR Sep-2025 Release 1) are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog as of October 2, 2025, indicating exploitation in the wild, and headlines note Samsung patched it as an actively exploited zero-day; a related Samsung image-codec zero-day (CVE-2025-21042) was used to deliver LANDFALL spyware.
What to do: Update affected Samsung devices to SMR Sep-2025 Release 1 or later via Settings > Software update, prioritizing devices exposed to untrusted image content (messaging, email, browsers). CISA KEV requires applying the vendor fix (or discontinuing use) under BOD 22-01 timelines for federal systems. Because exploitation has been observed in the wild and a related image-codec zero-day (CVE-2025-21042) was used to deploy LANDFALL spyware, verify fleet patch levels and investigate any devices showing signs of spyware infection.
| Samsung Mobile Devices (libimagecodec.quram.so, Android) | All Samsung Mobile Devices with security updates prior to SMR Sep-2025 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
- Affected
- Samsung Mobile Devices
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H