Executive brief
Samsung mobile devices contain a critical security flaw in a component responsible for processing images. An attacker could exploit this by sending a specially crafted image to a device, potentially allowing them to take full control of the phone or steal sensitive data. This vulnerability has been reported as being actively used in targeted attacks.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the 'libimagecodec.quram.so' library on Samsung Android devices. The flaw is triggered during the processing of malformed image files, allowing an attacker to overwrite memory and achieve arbitrary code execution. While NIST rates this as a network-based attack with no user interaction (CVSS 9.8), Samsung's advisory suggests user interaction may be required (CVSS 8.8). This vulnerability is notably included in CISA's Known Exploited Vulnerabilities (KEV) catalog and has been linked to commercial-grade spyware campaigns. A fix is available in the Samsung SMR April 2025 security update.
Affected products
- Samsung Android Prior to SMR Apr-2025 Release 1
Timeline
- 2025-04-01: patched: Addressed in Samsung SMR Apr-2025 Release 1
- 2025-09-12: disclosed: Initial NVD publication
- 2025-11-10: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-11-10: exploited: Confirmed active exploitation in the wild