ZeroHour
Security Affairspublished ()ingested @securityaffairs

Samsung fixed actively exploited zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-21043CVE-2025-55177CVE-2025-43300

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-21043
Out-of-Bounds Write RCE in Samsung Mobile Image Codec (libimagecodec.quram.so)

CVE-2025-21043 is an out-of-bounds write vulnerability (CWE-787) in libimagecodec.quram.so, the image-decoding library used by Samsung Mobile Devices. It can be triggered remotely when the vulnerable codec processes maliciously crafted image data, and per the CVSS vector it requires no privileges or user interaction. A successful attack allows a remote attacker to execute arbitrary code on the device with high impact on confidentiality, integrity, and availability (CVSS 9.8, critical). All Samsung mobile devices running a security update prior to the September 2025 Maintenance Release (SMR Sep-2025 Release 1) are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog as of October 2, 2025, indicating exploitation in the wild, and headlines note Samsung patched it as an actively exploited zero-day; a related Samsung image-codec zero-day (CVE-2025-21042) was used to deliver LANDFALL spyware.

Do: Update affected Samsung devices to SMR Sep-2025 Release 1 or later via Settings > Software update, prioritizing devices exposed to untrusted image content (messaging, email, browsers). CISA KEV requires applying the vendor fix (or discontinuing use) under BOD 22-01 timelines for federal systems. Because exploitation has been observed in the wild and a related image-codec zero-day (CVE-2025-21042) was used to deploy LANDFALL spyware, verify fleet patch levels and investigate any devices showing signs of spyware infection.

9.82% KEV
  • Samsung Mobile Devices (libimagecodec.quram.so, Android) All Samsung Mobile Devices with security updates prior to SMR Sep-2025 Release 1
masshundreds of millions to over 1 billion Samsung mobile devices (any device not yet on SMR Sep-2025 Release 1)
CVE-2025-43300
Actively Exploited Out-of-Bounds Write in Apple iOS/iPadOS/macOS Image I/O

CVE-2025-43300 is an out-of-bounds write (CWE-787) in the Image I/O (ImageIO) framework used by Apple iOS, iPadOS, and macOS. It can be triggered when a device processes a specially crafted image file, corrupting memory in the image-parsing process. Successful exploitation may cause application crashes or allow arbitrary code execution with the privileges of the application handling the image. Because ImageIO is a core system component on essentially every Apple device, virtually all users of iPhones, iPads, and Macs are exposed. The flaw is being exploited in the wild — CISA added it to the KEV catalog on 2025-08-21, mandating patching per BOD 22-01 for federal agencies — and EPSS estimates a 22% probability of exploitation in the next 30 days (98th percentile); no public PoC is known and ransomware use is unconfirmed.

Do: Apply Apple's security updates for iOS, iPadOS, and macOS issued in August 2025 (e.g., iOS 18.6.1 / iPadOS 18.6.1 and macOS Sequoia 15.6.1) on all devices, prioritizing user-facing fleets and agencies bound by BOD 22-01 deadlines. Until devices are patched, exercise caution with images from untrusted sources (email, messaging, web content), since no compensating mitigations are specified. Note that the source data does not enumerate exact affected builds, so verify coverage against Apple's advisory and CISA KEV required actions.

10.022% KEV PoC
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
mass>1 billion active Apple devices (ImageIO is a core framework on all iOS/iPadOS/macOS devices; Apple's active device base exceeds 2 billion)
CVE-2025-55177
Incorrect Authorization in WhatsApp Linked-Device Sync Used in Targeted Spyware Attacks

CVE-2025-55177 is an incorrect authorization flaw (CWE-863) in how WhatsApp for iOS, WhatsApp Business for iOS, and WhatsApp for Mac validate linked device synchronization messages, allowing an unrelated user to trigger processing of content from an arbitrary URL on a target's device. An attacker can reach a vulnerable client through the messaging channel without normal authorization checks, causing the app to fetch or process attacker-chosen content. On its own the flaw carries only partial confidentiality and integrity impact (CVSS 5.4), but Meta assesses it was chained with an Apple OS vulnerability (CVE-2025-43300) in a sophisticated attack against specific, targeted users. Users running WhatsApp for iOS before 2.25.21.73, WhatsApp Business for iOS before 2.25.21.78, or WhatsApp for Mac before 2.25.21.78 are affected. The flaw was added to CISA's KEV catalog on 2025-09-02 amid reports of highly targeted zero-day attacks, though no public proof-of-concept is known and use in ransomware campaigns has not been reported.

Do: Update WhatsApp for iOS to v2.25.21.73 or later, WhatsApp Business for iOS to v2.25.21.78 or later, and WhatsApp for Mac to v2.25.21.78 or later. Also apply Apple's backported OS fix for CVE-2025-43300, since the two flaws were combined in the observed attack chain. Review and re-link WhatsApp companion devices if compromise is suspected; federal agencies must follow BOD 22-01 required-action deadlines per the KEV listing.

5.44% KEV
  • Meta Platforms WhatsApp for iOS all versions prior to 2.25.21.73
  • Meta Platforms WhatsApp Business for iOS all versions prior to 2.25.21.78
  • Meta Platforms WhatsApp for Mac all versions prior to 2.25.21.78
masshundreds of millions of users (WhatsApp's multi-billion user base includes a very large iOS/macOS install base)
Full article316 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 12, 2025

Samsung fixed the remote code execution flaw CVE-2025-21043 that was exploited in zero-day attacks against Android devices.

Samsung addressed the remote code execution vulnerability, tracked as CVE-2025-21043, that was exploited in zero-day attacks against Android users.

The vulnerability is an out-of-bounds Write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1. A remote attacker can exploit the flaw to execute arbitrary code.

An out-of-bounds write occurs when a program writes data beyond the boundaries of its allocated memory buffer, which can corrupt data, crash the program, or allow code execution by attackers.

The vulnerability was reported by the security teams of Meta and WhatsApp on August 13.

Samsung released a patch to fix the incorrect implementation.

In late August, WhatsApp sent out a round of threat notifications to individuals they believe were targeted by an advanced spyware campaign in the past 90 days. WhatsApp warned some users that a malicious message may have exploited OS flaws to compromise devices and data.

The attack requires no user interaction, meaning victims could be compromised without clicking a link or downloading a file. Such exploits are typically linked to well-resourced threat actors, including state-sponsored groups. WhatsApp urges recipients of the notification to review their devices for unusual behavior, update to the latest version, and enable enhanced security measures to reduce the risk of further compromise.

WhatsApp announced that it had already patched the flaw exploited by attackers, but risks remain.

Amnesty researchers who are investigating the attack report that the exploit targets an authorization bypass issue, tracked as CVE-2025-55177, in WhatsApp on iOS and Mac. The exploit allowed attackers to force “content from arbitrary URL” to be rendered on a target device. Threat actors also exploited a zero-click vulnerability, recently patched by Apple (CVE-2025-43300), in the attacks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Meta)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/182135/hacking/samsung-fixed-actively-exploited-zero-day.html