ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

CISA Adds Zero

criticalAdvisory exploited in the wildimportance 60CVE-2025-21042CVE-2025-21043

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-21042
+1 in the same advisory: …21043
Out-of-Bounds Write RCE in Samsung Mobile Image Codec (libimagecodec.quram.so)

CVE-2025-21042 is an out-of-bounds write (CWE-787) in libimagecodec.quram.so, the Quram image codec library in the image-processing stack of Samsung mobile devices. A remote attacker can trigger the flaw by getting a vulnerable device to decode a crafted image or media file, corrupting memory and potentially executing arbitrary code (the advisory does not specify the exact delivery vector, such as messaging or web content). Successful exploitation allows the attacker to run code on the device, though whether execution is confined to the decoding application or achieves broader privileges is not stated. Any Samsung mobile device using the affected codec is potentially at risk; CISA lists the product only as 'Samsung Mobile Devices' without model or version detail. The flaw is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2025-11-10 (ransomware use unknown), no public PoC is known, and EPSS assigns a 33.2% probability of exploitation within 30 days (98th percentile).

Do: Install the latest Samsung security maintenance release (SMR) / monthly security update on all Samsung mobile devices and verify each device's Android security patch level includes the fix for this CVE; per CISA's KEV required action, apply the vendor's mitigations, and federal civilian agencies must follow BOD 22-01 or discontinue use of affected products. Until the update is confirmed, treat untrusted image/media files (e.g., received via messaging or web) as a risk vector on Samsung devices and monitor Samsung's security advisories for the affected-model list.

9.833% KEV
  • Samsung Mobile Devices
masshundreds of millions to roughly a billion Samsung mobile devices in use worldwide (order of magnitude 10^8-10^9)
Full article322 words · extracted from infosecurity-magazine.com · click to collapse

US federal agencies have been told to patch a zero-day vulnerability used by threat actors since last year to deploy spyware to Samsung devices.

The out-of-bounds write flaw CVE-2025-21042 has a CVSS score of 9.8 and was patched by Samsung in April. However, an analysis by Palo Alto Networks published last week claimed it had been used in a spyware campaign since mid-2024.

During that campaign, commercial-grade spyware known as LandFall was embedded in malicious DNG image files and sent via WhatsApp to targets. Zero-click exploits may have been used to achieve remote code execution without any user interaction, Palo Alto said.

“This method closely resembles an exploit chain involving Apple and WhatsApp that drew attention in August 2025,” it added.

“It also resembles an exploit chain that likely occurred using a similar zero-day vulnerability (CVE-2025-21043) disclosed in September. Our research did not identify any unknown vulnerabilities in WhatsApp.”

Read more on commercial spyware: France Warns Apple Users of New Spyware Campaign

According to Palo Alto’s analysis, LandFall is primarily designed to target victims in the Middle East and enables “comprehensive surveillance, including microphone recording, location tracking and collection of photos, contacts and call logs.”

The report adds: “The campaign shares infrastructure and tradecraft patterns with commercial spyware operations in the Middle East, indicating possible links to private-sector offensive actors (PSOAs).”

At risk are a wide range of Samsung devices, including Galaxy S22, S23, and S24, and Z Fold4 and Z Flip4.

CISA KEV Sets Deadline Date

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-21042 to its Known Exploited Vulnerabilities (KEV) catalog yesterday.

It requires federal agencies to take the following actions by December 1: “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”

Private sector organizations are also encouraged to follow KEV guidance where possible to improve their security posture.

Image credit: viewimage / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-zeroday-bugspyware-attacks-kev/