PT-2025-37297 · Samsung +1 · Samsung Quram Image Codec +1

Published

2025-08-13

·

Updated

2025-11-13

·

CVE-2025-21043

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung devices versions Android 13 through 16
Description A critical out-of-bounds write vulnerability exists in the libimagecodec.quram.so library, potentially allowing remote attackers to execute arbitrary code on vulnerable devices. This flaw was actively exploited in attacks, with reports indicating exploitation via malicious images, potentially through messaging applications like WhatsApp. The vulnerability was reported by Meta and WhatsApp security teams and has been addressed in the September 2025 security update. The vulnerability affects Samsung Galaxy devices and has been exploited in the wild.
Recommendations Install the September 2025 security update on all affected devices.

Fix

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-15409
CVE-2025-21043

Affected Products

Android
Samsung Quram Image Codec