Vulnerability record · CVE-2025-21042 · published 12 September 2025
CVE-2025-21042: Samsung Android libimagecodec.quram.so out-of-bounds write
Samsung · Android
An out-of-bounds write in Samsung's libimagecodec.quram.so image codec library, fixed in the SMR Apr-2025 Release 1, allows remote attackers to execute arbitrary code. The flaw is remotely reachable with no privileges or user interaction, and it has been added to CISA's Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.
Description
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, and confirmed exploitation in CISA KEV make this a critical patching priority.
What it is
An out-of-bounds write in Samsung's libimagecodec.quram.so image codec library, fixed in the SMR Apr-2025 Release 1, allows remote attackers to execute arbitrary code. The flaw is remotely reachable with no privileges or user interaction, and it has been added to CISA's Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.
Impact
A successful attack can execute arbitrary code in the context of the affected process, giving the attacker code execution on the device. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The CVSS vector is network-based with no privileges and no user interaction required, so it is reachable remotely without authentication. The description does not state the exact delivery path, but the affected component is an image codec library, so processing attacker-supplied image data is the likely vector.
Exploitation
CVE-2025-21042 is listed in CISA KEV with a due date of 2025-12-01, confirming known exploitation. EPSS gives a 30-day probability of 0.3317 (98.3rd percentile), and a third-party advisory links it to Android spyware activity.
What to do
- Apply the Samsung SMR Apr-2025 Release 1 (or later) security update to affected devices as the first action.
- If patching cannot be done immediately, follow CISA KEV required actions and BOD 22-01 guidance, including discontinuing use of unpatched devices where no mitigation exists.
- Restrict or monitor delivery of untrusted image files to affected devices until patched.
- Track device fleet patch compliance against the SMR Apr-2025 Release 1 baseline and prioritize unpatched, internet-exposed devices.
Detection
- Monitor for crashes or abnormal behavior in processes loading libimagecodec.quram.so, which may indicate exploitation attempts.
- Hunt for unexpected code execution or anomalous child processes spawned from media or image handling components on Samsung Android devices.
- Review mobile threat defense or EDR telemetry for known Android spyware indicators associated with this vulnerability, using the Unit 42 advisory as a reference.
- Check device build versions against the SMR Apr-2025 Release 1 patch level to identify unpatched assets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-21042 to the Known Exploited Vulnerabilities catalog on 10 November 2025 as "Samsung Mobile Devices Out-of-Bounds Write Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 December 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=04 | Vendor Advisory |
| https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/ | Technical DescriptionThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-21042 | US Government Resource |
Track CVE-2025-21042 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-21042), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.