
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-21043 is a critical out-of-bounds write vulnerability in Samsung's libimagecodec.quram.so image codec library that allows remote attackers to execute arbitrary code on affected Android devices. It affects Samsung Android versions 13, 14, 15, and 16 across numerous Security Maintenance Releases (SMRs) prior to SMR Sep-2025 Release 1. The vulnerability was publicly disclosed on September 12, 2025, and patched in Samsung's September 2025 security update. It carries a CVSS v3.1 base score of 9.8 (Critical) (Samsung Advisory, CISA KEV).
The root cause is an out-of-bounds write (CWE-787) in Samsung's proprietary Quram image codec library (libimagecodec.quram.so), which is responsible for parsing image formats including DNG (Digital Negative) files. Attackers can craft malicious DNG image files containing specially structured opcodes that trigger the memory corruption when parsed by the library. Notably, this vulnerability can be triggered zero-click via WhatsApp — when a victim receives a malicious image, WhatsApp automatically processes it using the vulnerable codec without any user interaction required. No authentication or privileges are needed for exploitation (msuiche blog, The Hacker News, Unit 42).
Successful exploitation grants remote attackers full arbitrary code execution on the target Samsung Android device with no user interaction required. This enables complete device compromise — including access to sensitive data, credentials, messages, and system functions — as well as the ability to install persistent spyware or malware. The vulnerability was weaponized to deploy LANDFALL, a commercial-grade Android spyware, targeting Samsung Galaxy users primarily in the Middle East, with the attack chain delivered silently through WhatsApp image messages (Unit 42, BleepingComputer, Security Affairs).
libimagecodec.quram.so when parsed.libimagecodec.quram.so, corrupting adjacent memory and enabling control flow hijacking.mediaserver, libimagecodec-related processes); unexpected privilege escalation activity.libimagecodec.quram.so or media processing components around the time of receiving a WhatsApp image; logcat entries indicating memory access violations in the Quram codec.Samsung released fixes in the September 2025 Security Maintenance Release (SMR Sep-2025 Release 1) for Android 13, 14, 15, and 16. Users should immediately update to Android 13.0-smr-sep-2025-r1, 14.0-smr-sep-2025-r1, 15.0-smr-sep-2025-r1, or 16.0-smr-sep-2025-r1 or later via Settings > Software Update. CISA mandated that federal agencies apply the patch by October 23, 2025 per BOD 22-01 (CISA KEV, Samsung Advisory). Until patching is complete, organizations should advise users to exercise caution with WhatsApp images from unknown senders and consider network-level monitoring for anomalous outbound traffic from mobile devices.
The vulnerability received widespread media coverage from major outlets including Forbes, ZDNet, PCMag, Mashable, The Register, and SecurityWeek, reflecting its high severity and zero-click nature (SecurityWeek, ZDNet). Palo Alto Networks Unit 42 published a detailed threat intelligence report on the LANDFALL spyware campaign that weaponized this flaw, providing significant technical attribution (Unit 42). Security researcher Matt Suiche (msuiche) published a notable technical analysis titled 'When DNG Opcodes Become Attack Vectors,' detailing the exploitation mechanics (msuiche blog). The vulnerability was also presented at the 39C3 (Chaos Communication Congress 2025) conference in a talk titled 'DNGerousLINK: A Deep Dive into WhatsApp 0-Click Exploits on iOS and Samsung Devices,' underscoring its significance to the research community (CCC Media). Community reaction on Reddit and social media was significant, with users urgently discussing the need to update Samsung Galaxy devices.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."