PT-2025-37296 · Samsung · Libimagecodec.Quram.So
Published
2024-09-25
·
Updated
2026-02-25
·
CVE-2025-21042
CVSS v3.1
10
10
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung Galaxy devices versions prior to April 2025 Security Maintenance Release (SMR Apr-2025 Release 1)
Samsung Galaxy S10e (not affected)
Samsung Galaxy S22, S23, S24
Samsung Galaxy Z Fold4
Samsung Galaxy Z Flip4
Description
A critical out-of-bounds write vulnerability exists in the
libimagecodec.quram.so library of Samsung Galaxy devices, allowing remote attackers to execute arbitrary code. This flaw, identified as CVE-2025-21042, was actively exploited in the wild as a zero-day to deliver the LANDFALL spyware. The attack vector involved specially crafted DNG image files, often delivered via WhatsApp, exploiting a flaw in the image processing library. The spyware enables comprehensive surveillance, including access to microphone recordings, location data, photos, contacts, and call logs. The campaign primarily targeted individuals in the Middle East, including Iraq, Iran, Turkey, and Morocco. The exploit chain potentially operated without user interaction (zero-click). The vulnerability was patched in the April 2025 Security Maintenance Release (SMR Apr-2025 Release 1).Recommendations
Update Samsung Galaxy devices to the April 2025 Security Maintenance Release (SMR Apr-2025 Release 1) or later.
Disable auto-download of multimedia in messaging applications.
Avoid opening unknown DNG/RAW files.
Consider disabling the vulnerable image processing library if possible.
Fix
LPE
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
BDU:2025-14812
CVE-2025-21042
Affected Products
Libimagecodec.Quram.So
References · 171
- https://bdu.fstec.ru/vul/2025-14812 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-21042 · Security Note
- https://twitter.com/CVEnew/status/1966405803599917430 · Twitter Post
- https://twitter.com/AnonOzzyDude/status/1987126414580085245 · Twitter Post
- https://twitter.com/grok/status/1987301874941501848 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1q6cj0c/top_10_trending_cves_07012026 · Reddit Post
- https://twitter.com/rst_cloud/status/1988762693117870088 · Twitter Post
- https://t.me/cKure/16557 · Telegram Post
- https://twitter.com/Unit42_Intel/status/1986826213067739184 · Twitter Post
- https://twitter.com/SempreUpdate/status/1987860695996649799 · Twitter Post
- https://twitter.com/securityaffairs/status/1987106024344723532 · Twitter Post
- https://twitter.com/ZeroPathLabs/status/1966418474940367116 · Twitter Post
- https://twitter.com/dailytechonx/status/1988304226410266722 · Twitter Post
- https://twitter.com/CyberWolfGuard/status/1987265883295613313 · Twitter Post
- https://twitter.com/transilienceai/status/1991385555775492558 · Twitter Post