CVE-2025-21042

9.5 CISA KEV

Samsung · Mobile Devices

A critical out-of-bounds write vulnerability in the Samsung libimagecodec.quram.so library allows remote attackers to execute arbitrary code via specially crafted image files.

Executive summary

Samsung mobile devices are vulnerable to a critical remote code execution flaw that is currently being actively exploited in the wild via the LANDFALL spyware campaign.

Vulnerability

This vulnerability consists of an out-of-bounds write flaw within the libimagecodec.quram.so component. The attack vector is remote and requires no user interaction, allowing unauthenticated attackers to execute arbitrary code on the target device.

Business impact

The exploitation of this vulnerability poses a severe risk to organizational security, as it allows for full device compromise and potential data exfiltration. With a CVSS score of 9.5, this is a critical-severity issue that could lead to significant reputational damage and the loss of sensitive corporate information stored on mobile assets. Its inclusion in the CISA Known Exploited Vulnerabilities catalog underscores the immediate risk to enterprise environments.

Remediation

Immediate Action: Update all affected Samsung mobile devices to the SMR Apr-2025 Release 1 or later version immediately.

Proactive Monitoring: Monitor mobile device management (MDM) logs for unusual application behavior or unexpected crashes related to image processing services.

Compensating Controls: Ensure that third-party application stores are restricted and utilize mobile threat defense (MTD) solutions to detect malicious payloads or anomalous system calls.

Exploitation status

Public Exploit Available: Yes, multiple public Proof-of-Concept repositories are available on GitHub.

Analyst recommendation

The active exploitation of this vulnerability in the wild makes it a top-tier priority for security teams. Organizations must verify that all managed Samsung devices are updated to the SMR Apr-2025 Release 1 or higher. Failure to apply this patch leaves devices highly susceptible to sophisticated spyware campaigns that can bypass standard user-interaction barriers.

More Samsung CVEs

Sources