Junglewise Threat Intelligence

CVE-2025-21043: Samsung Mobile Devices out-of-bounds write in libimagecodec.quram.so

CVE-2025-21043 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-10-02

Technologies: Samsung Mobile Devices. Vendors: Samsung.

Executive brief

Samsung mobile devices contain a critical security flaw in a component responsible for processing images. An attacker could exploit this vulnerability to remotely take control of a device or execute unauthorized commands. This issue is particularly serious as it has been reported to be actively exploited in the wild.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the libimagecodec.quram.so library on Samsung mobile devices. The flaw is triggered during the processing of malformed image files, allowing a remote attacker to overwrite memory and achieve arbitrary code execution. While some assessments suggest user interaction (UI:R) may be required to trigger the image processing, NIST has rated this as a network-based attack with no privileges required. The vulnerability was addressed in the Samsung SMR September 2025 security update. CISA has confirmed active exploitation of this flaw.

Affected products

  • Samsung Android Prior to SMR Sep-2025 Release 1

Timeline

  • 2025-09-12: disclosed: Initial disclosure by Samsung Mobile
  • 2025-09-12: patched: Addressed in SMR Sep-2025 Release 1
  • 2025-10-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats