ZeroHour

CVE-2025-21043

KEVmass2

Out-of-Bounds Write RCE in Samsung Mobile Image Codec (libimagecodec.quram.so)

CISA: Samsung Mobile Devices Out-of-Bounds Write Vulnerability

CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
KEV added
AI analysis

CVE-2025-21043 is an out-of-bounds write vulnerability (CWE-787) in libimagecodec.quram.so, the image-decoding library used by Samsung Mobile Devices. It can be triggered remotely when the vulnerable codec processes maliciously crafted image data, and per the CVSS vector it requires no privileges or user interaction. A successful attack allows a remote attacker to execute arbitrary code on the device with high impact on confidentiality, integrity, and availability (CVSS 9.8, critical). All Samsung mobile devices running a security update prior to the September 2025 Maintenance Release (SMR Sep-2025 Release 1) are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog as of October 2, 2025, indicating exploitation in the wild, and headlines note Samsung patched it as an actively exploited zero-day; a related Samsung image-codec zero-day (CVE-2025-21042) was used to deliver LANDFALL spyware.

What to do: Update affected Samsung devices to SMR Sep-2025 Release 1 or later via Settings > Software update, prioritizing devices exposed to untrusted image content (messaging, email, browsers). CISA KEV requires applying the vendor fix (or discontinuing use) under BOD 22-01 timelines for federal systems. Because exploitation has been observed in the wild and a related image-codec zero-day (CVE-2025-21042) was used to deploy LANDFALL spyware, verify fleet patch levels and investigate any devices showing signs of spyware infection.

Affected
Samsung Mobile Devices (libimagecodec.quram.so, Android)All Samsung Mobile Devices with security updates prior to SMR Sep-2025 Release 1
Estimated exposure
masshundreds of millions to over 1 billion Samsung mobile devices (any device not yet on SMR Sep-2025 Release 1) — Samsung is the world's largest Android vendor with roughly a fifth of global smartphone market share and a multi-billion-device cumulative install base, and the vulnerable image codec ships across its supported models until the September…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Samsung Mobile Devices
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
samsung
Products
android
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news