← Vulnerability feed

Vulnerability record · CVE-2025-21042 · published 12 September 2025

CVE-2025-21042: Samsung Android libimagecodec.quram.so out-of-bounds write

Samsung · Android

An out-of-bounds write in Samsung's libimagecodec.quram.so image codec library, fixed in the SMR Apr-2025 Release 1, allows remote attackers to execute arbitrary code. The flaw is remotely reachable with no privileges or user interaction, and it has been added to CISA's Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.

9.8 CVSS 3.1 Critical CISA KEV since 10 Nov 2025 EPSS 33% · top 1.7% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
33%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, and confirmed exploitation in CISA KEV make this a critical patching priority.

What it is

An out-of-bounds write in Samsung's libimagecodec.quram.so image codec library, fixed in the SMR Apr-2025 Release 1, allows remote attackers to execute arbitrary code. The flaw is remotely reachable with no privileges or user interaction, and it has been added to CISA's Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.

Impact

A successful attack can execute arbitrary code in the context of the affected process, giving the attacker code execution on the device. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The CVSS vector is network-based with no privileges and no user interaction required, so it is reachable remotely without authentication. The description does not state the exact delivery path, but the affected component is an image codec library, so processing attacker-supplied image data is the likely vector.

Exploitation

CVE-2025-21042 is listed in CISA KEV with a due date of 2025-12-01, confirming known exploitation. EPSS gives a 30-day probability of 0.3317 (98.3rd percentile), and a third-party advisory links it to Android spyware activity.

What to do

  • Apply the Samsung SMR Apr-2025 Release 1 (or later) security update to affected devices as the first action.
  • If patching cannot be done immediately, follow CISA KEV required actions and BOD 22-01 guidance, including discontinuing use of unpatched devices where no mitigation exists.
  • Restrict or monitor delivery of untrusted image files to affected devices until patched.
  • Track device fleet patch compliance against the SMR Apr-2025 Release 1 baseline and prioritize unpatched, internet-exposed devices.

Detection

  • Monitor for crashes or abnormal behavior in processes loading libimagecodec.quram.so, which may indicate exploitation attempts.
  • Hunt for unexpected code execution or anomalous child processes spawned from media or image handling components on Samsung Android devices.
  • Review mobile threat defense or EDR telemetry for known Android spyware indicators associated with this vulnerability, using the Unit 42 advisory as a reference.
  • Check device build versions against the SMR Apr-2025 Release 1 patch level to identify unpatched assets.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-21042 to the Known Exploited Vulnerabilities catalog on 10 November 2025 as "Samsung Mobile Devices Out-of-Bounds Write Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 December 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-21042 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-21043Samsung Android libimagecodec Out-of-Bounds Write RCEAn out-of-bounds write in libimagecodec.quram.so, a Samsung image codec library on Android, allows remote code execution. The flaw is reachable witho…KEVEPSS 2.1%analysed7.8CVE-2021-25487Samsung Android modem driver buffer bounds flaw enables code executionThe modem interface driver in Samsung Android fails to bounds-check a buffer in set_skb_priv(), allowing an out-of-bounds read. The read can derefere…KEVEPSS 0.64%analysed7.1CVE-2021-25337Samsung clipboard service access control flaw exposes local filesSamsung mobile devices before SMR Mar-2021 Release 1 have improper access control in the clipboard service, letting untrusted applications read or wr…KEVEPSS 2.8%analysed6.7CVE-2021-25371Samsung Android DSP driver allows loading arbitrary ELF librariesThe DSP driver in Samsung Android devices before SMR Mar-2021 Release 1 permits loading of arbitrary ELF libraries inside the DSP. This breaks the in…KEVEPSS 0.80%analysed6.7CVE-2021-25372Samsung Android DSP driver improper boundary check allows out-of-bounds memory accessThe Samsung DSP driver in Android contains an improper boundary check that permits out-of-bounds memory access. The flaw is fixed in SMR Mar-2021 Rel…KEVEPSS 0.80%analysed6.4CVE-2021-25395Samsung Android MFC charger driver race condition bypasses signature checkA race condition in the Samsung MFC charger driver, fixed prior to SMR MAY-2021 Release 1, lets a local attacker bypass a signature check. It matters…KEVEPSS 0.37%analysed6.4CVE-2021-25394Samsung Android MFC charger driver use-after-free via race conditionThe MFC charger driver in Samsung Android contains a use-after-free that can be triggered through a race condition. It allows an arbitrary write, but…KEVEPSS 0.40%analysed5.5CVE-2021-25489Samsung Android modem driver format string bug causes kernel panicSamsung Android devices contain a missing input validation flaw in the modem interface driver, resulting in a format string bug. It is listed in CISA…KEVEPSS 0.53%analysed

Source: NIST National Vulnerability Database (record CVE-2025-21042), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.