Executive brief
Samsung mobile devices contain a critical security flaw in a component responsible for processing images. An attacker could exploit this vulnerability to remotely take control of a device or execute unauthorized commands. This issue is particularly serious as it has been reported to be actively exploited in the wild.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the libimagecodec.quram.so library on Samsung mobile devices. The flaw is triggered during the processing of malformed image files, allowing a remote attacker to overwrite memory and achieve arbitrary code execution. While some assessments suggest user interaction (UI:R) may be required to trigger the image processing, NIST has rated this as a network-based attack with no privileges required. The vulnerability was addressed in the Samsung SMR September 2025 security update. CISA has confirmed active exploitation of this flaw.
Affected products
- Samsung Android Prior to SMR Sep-2025 Release 1
Timeline
- 2025-09-12: disclosed: Initial disclosure by Samsung Mobile
- 2025-09-12: patched: Addressed in SMR Sep-2025 Release 1
- 2025-10-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog