Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
https://www.theregister.com/2025/09/16/apple_0day_spy_attacks/
https://www.securityweek.com/samsung-patches-zero-day-exploited-against-android-users/
https://hackread.com/samsung-android-image-parsing-vulnerability-attacks/
https://www.theregister.com/2025/09/12/samsung_fixes_android_0day/
https://thehackernews.com/2025/09/samsung-fixes-critical-zero-day-cve.html
https://securityaffairs.com/182135/hacking/samsung-fixed-actively-exploited-zero-day.html