CVE-2025-21043

critical

Description

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

References

https://www.malwarebytes.com/blog/news/2025/11/patch-now-samsung-zero-day-lets-attackers-take-over-your-phone

https://www.infosecurity-magazine.com/news/cisa-zeroday-bugspyware-attacks-kev/

https://www.helpnetsecurity.com/2025/11/11/samsung-spyware-cve-2025-21042/

https://securityaffairs.com/184452/hacking/u-s-cisa-adds-samsung-mobile-devices-flaw-to-its-known-exploited-vulnerabilities-catalog.html

https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-samsung-zero-day-used-in-spyware-attacks/

https://hackread.com/landfall-spyware-samsung-galaxy-malicious-images/

https://www.theregister.com/2025/11/07/landfall_spyware_samsung_0days/

https://www.securityweek.com/landfall-android-spyware-targeted-samsung-phones-via-zero-day/

https://www.darkreading.com/mobile-security/landfall-malware-targeted-samsung-galaxy-users

https://www.bleepingcomputer.com/news/security/new-landfall-spyware-exploited-samsung-zero-day-via-whatsapp-messages/

https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/

https://thehackernews.com/2025/11/samsung-zero-click-flaw-exploited-to.html

https://securityaffairs.com/184331/security/landfall-spyware-exploited-samsung-zero-day-cve-2025-21042-in-middle-east-attacks.html

https://www.securityweek.com/organizations-warned-of-exploited-meteobridge-vulnerability/

https://thehackernews.com/2025/10/cisa-flags-meteobridge-cve-2025-4008.html

https://www.cisa.gov/news-events/alerts/2025/10/02/cisa-adds-five-known-exploited-vulnerabilities-catalog

https://www.theregister.com/2025/09/16/apple_0day_spy_attacks/

https://www.securityweek.com/samsung-patches-zero-day-exploited-against-android-users/

https://hackread.com/samsung-android-image-parsing-vulnerability-attacks/

https://www.theregister.com/2025/09/12/samsung_fixes_android_0day/

https://www.bleepingcomputer.com/news/security/samsung-patches-actively-exploited-zero-day-reported-by-whatsapp/

https://thehackernews.com/2025/09/samsung-fixes-critical-zero-day-cve.html

https://securityaffairs.com/182135/hacking/samsung-fixed-actively-exploited-zero-day.html

Details

Source: Mitre, NVD

Published: 2025-09-12

Updated: 2025-10-30

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.1144