CVE-2025-21043
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-21043 is a critical out-of-bounds write vulnerability in Samsung's libimagecodec.quram.so image codec library that allows remote attackers to execute arbitrary code on affected Android devices. It affects Samsung Android versions 13, 14, 15, and 16 across numerous Security Maintenance Releases (SMRs) prior to SMR Sep-2025 Release 1. The vulnerability was publicly disclosed on September 12, 2025, and patched in Samsung's September 2025 security update. It carries a CVSS v3.1 base score of 9.8 (Critical) (Samsung Advisory, CISA KEV).

Technical details

The root cause is an out-of-bounds write (CWE-787) in Samsung's proprietary Quram image codec library (libimagecodec.quram.so), which is responsible for parsing image formats including DNG (Digital Negative) files. Attackers can craft malicious DNG image files containing specially structured opcodes that trigger the memory corruption when parsed by the library. Notably, this vulnerability can be triggered zero-click via WhatsApp — when a victim receives a malicious image, WhatsApp automatically processes it using the vulnerable codec without any user interaction required. No authentication or privileges are needed for exploitation (msuiche blog, The Hacker News, Unit 42).

Impact

Successful exploitation grants remote attackers full arbitrary code execution on the target Samsung Android device with no user interaction required. This enables complete device compromise — including access to sensitive data, credentials, messages, and system functions — as well as the ability to install persistent spyware or malware. The vulnerability was weaponized to deploy LANDFALL, a commercial-grade Android spyware, targeting Samsung Galaxy users primarily in the Middle East, with the attack chain delivered silently through WhatsApp image messages (Unit 42, BleepingComputer, Security Affairs).

Exploitation steps

  1. Craft malicious DNG image: The attacker creates a specially crafted DNG (Digital Negative) image file containing malicious opcodes designed to trigger an out-of-bounds write in Samsung's libimagecodec.quram.so when parsed.
  2. Deliver via WhatsApp: The attacker sends the malicious DNG image to the target's WhatsApp account. WhatsApp automatically processes incoming media files, invoking the vulnerable Quram image codec library without any user interaction (zero-click).
  3. Trigger memory corruption: When the device processes the image, the malformed DNG opcodes cause an out-of-bounds write in libimagecodec.quram.so, corrupting adjacent memory and enabling control flow hijacking.
  4. Achieve arbitrary code execution: The memory corruption is leveraged to redirect execution to attacker-controlled code, achieving remote code execution in the context of the media processing service.
  5. Deploy payload: The attacker drops and installs a persistent payload — in confirmed attacks, the LANDFALL commercial spyware — which exfiltrates messages, contacts, location data, and other sensitive information from the compromised device (msuiche blog, Unit 42, The Hacker News).

Indicators of compromise

  • Network: Unexpected outbound connections from the device to unknown command-and-control infrastructure following receipt of a WhatsApp image message; unusual data exfiltration patterns (contacts, SMS, location) to external IPs.
  • File System: Presence of LANDFALL spyware components or unfamiliar APKs installed without user consent; suspicious files in media cache directories associated with malformed DNG images; new persistent services or daemons not associated with legitimate apps.
  • Process: Unusual child processes spawned by WhatsApp or media processing services (e.g., mediaserver, libimagecodec-related processes); unexpected privilege escalation activity.
  • Logs: Android system logs showing crashes or exceptions in libimagecodec.quram.so or media processing components around the time of receiving a WhatsApp image; logcat entries indicating memory access violations in the Quram codec.
  • Device Behavior: Unexplained battery drain, increased data usage, or device slowdown following receipt of a Whatsapp image from an unknown sender (Unit 42, Zimperium, Lookout).

Mitigation and workarounds

Samsung released fixes in the September 2025 Security Maintenance Release (SMR Sep-2025 Release 1) for Android 13, 14, 15, and 16. Users should immediately update to Android 13.0-smr-sep-2025-r1, 14.0-smr-sep-2025-r1, 15.0-smr-sep-2025-r1, or 16.0-smr-sep-2025-r1 or later via Settings > Software Update. CISA mandated that federal agencies apply the patch by October 23, 2025 per BOD 22-01 (CISA KEV, Samsung Advisory). Until patching is complete, organizations should advise users to exercise caution with WhatsApp images from unknown senders and consider network-level monitoring for anomalous outbound traffic from mobile devices.

Community reactions

The vulnerability received widespread media coverage from major outlets including Forbes, ZDNet, PCMag, Mashable, The Register, and SecurityWeek, reflecting its high severity and zero-click nature (SecurityWeek, ZDNet). Palo Alto Networks Unit 42 published a detailed threat intelligence report on the LANDFALL spyware campaign that weaponized this flaw, providing significant technical attribution (Unit 42). Security researcher Matt Suiche (msuiche) published a notable technical analysis titled 'When DNG Opcodes Become Attack Vectors,' detailing the exploitation mechanics (msuiche blog). The vulnerability was also presented at the 39C3 (Chaos Communication Congress 2025) conference in a talk titled 'DNGerousLINK: A Deep Dive into WhatsApp 0-Click Exploits on iOS and Samsung Devices,' underscoring its significance to the research community (CCC Media). Community reaction on Reddit and social media was significant, with users urgently discussing the need to update Samsung Galaxy devices.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16412CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesJul 21, 2026
CVE-2026-16411CRITICAL9.8
  • NixOS logoNixOS
  • mozjs38
NoYesJul 21, 2026
CVE-2026-16410CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026
CVE-2026-16408CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026
CVE-2026-16409HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management