Vulnerability record · CVE-2025-21043 · published 12 September 2025
CVE-2025-21043: Samsung Android libimagecodec Out-of-Bounds Write RCE
Samsung · Android
An out-of-bounds write in libimagecodec.quram.so, a Samsung image codec library on Android, allows remote code execution. The flaw is reachable without authentication or user interaction over the network, and Samsung fixed it in the September 2025 SMR release. Because it is a memory corruption bug in a widely deployed image parsing component, it is a serious remote code execution risk for unpatched Samsung devices.
Description
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, and confirmed inclusion in CISA KEV make this a top remediation priority.
What it is
An out-of-bounds write in libimagecodec.quram.so, a Samsung image codec library on Android, allows remote code execution. The flaw is reachable without authentication or user interaction over the network, and Samsung fixed it in the September 2025 SMR release. Because it is a memory corruption bug in a widely deployed image parsing component, it is a serious remote code execution risk for unpatched Samsung devices.
Impact
A remote attacker can execute arbitrary code in the context of the affected process, potentially gaining control of the device or its data. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The CVSS vector is AV:N/AC:L/PR:N/UI:N, so the flaw is network reachable with no authentication and no user interaction required. The description does not specify the exact entry point, but it is in an image codec library, so crafted image data processed by the device is the likely vector.
Exploitation
CVE-2025-21043 was added to CISA KEV on 2025-10-02 with a remediation due date of 2025-10-23, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.01907 (78.7th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Samsung SMR Sep-2025 Release 1 (or later) security update to affected devices.
- If patching is not immediately possible, follow CISA BOD 22-01 guidance and consider discontinuing use of unpatched devices for sensitive work.
- Restrict or monitor untrusted image file delivery to Samsung devices where feasible.
- Track device fleet patch compliance against the vendor advisory to confirm all units are updated.
Detection
- Monitor for crashes or abnormal terminations in processes loading libimagecodec.quram.so.
- Hunt for unexpected child processes or code execution spawned from image-handling components on Samsung devices.
- Review mobile threat defense or EDR telemetry for exploitation attempts against Samsung image parsing paths.
- Correlate device patch level against the September 2025 SMR baseline to find unpatched endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-21043 to the Known Exploited Vulnerabilities catalog on 2 October 2025 as "Samsung Mobile Devices Out-of-Bounds Write Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 October 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=09 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-21043 | US Government Resource |
Track CVE-2025-21043 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-21043), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.