🟢 CVE-2025-21042

CVE-2025-21042 is an out-of-bounds write vulnerability in Samsung mobile devices' image processing library that requires user interaction with malicious DNG image files. While actively exploited via messaging apps like WhatsApp, it targets client devices rather than internet-facing servers.

← Back to Overview
LOW_RISK
Risk Level
8.8
CVSS Score
NETWORK
Attack Vector
Execution
ATT&CK Tactic
T1203 — Exploitation for Client Execution
ATT&CK Technique
VERY_LOW
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: USER_INTERACTION

CVE Published: 2025-09-12

Added to CISA KEV: 2025-11-10 59 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2025-11-10)

CVE-2025-21042 is a critical zero-day vulnerability in Samsung's Android image processing library (`libimagecodec.quram.so`) that has been actively exploited in the wild [6][1]. Here's a breakdown of what is known about its exploitation:

  • Affected Applications/Services: The vulnerability affects Samsung Galaxy devices and is exploited through specially crafted DNG image files [3][7]. These images are often delivered via messaging applications like WhatsApp [11][8].
  • Active Exploitation: There is evidence of active exploitation in the wild. The vulnerability has been exploited by a commercial-grade spyware called LANDFALL [6][1].
  • Attack Vectors/Exploitation Methods:
* The primary attack vector involves sending a malformed DNG image file to the victim [6][8]. * The vulnerability is triggered when the device processes the image, leading to an out-of-bounds write error in the `libimagecodec.quram.so` component [4][2]. * Successful exploitation allows for remote code execution (RCE), enabling attackers to execute arbitrary code on the affected device [10][2]. * The exploit can be zero-click, requiring no user interaction beyond auto-download or viewing the image [9][7].
  • Targeted Attacks: The vulnerability has been used in targeted attacks, particularly against Samsung Galaxy users in the Middle East [3].
  • CISA KEV Status: As of November 10, 2025, there is no information indicating that CVE-2025-21042 has been added to the CISA Known Exploited Vulnerabilities (KEV) Catalog.
  • Technical Details/Internet Exploitability:
* CVE-2025-21042 is considered an easy target for cybercriminals due to its low attack complexity and no required privileges [5]. * The vulnerability has a high severity rating with a CVSS score of 8.8 [2]. * It involves an out-of-bounds write flaw in the `libimagecodec.quram.so` component [4][2]. * The vulnerability was patched by Samsung in April 2025 [12][13].

Sources

  1. Unit 42 - Latest Cybersecurity Research | Palo Alto Networks

    Commercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android’s image processing library.The silhouette of a bull facing the reviewer and the Taurus constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing spac…

  2. ⚡ Weekly Recap: Hyper-V Malware, Malicious AI Bots, RDP Exploits ...

    The activity involved the exploitation of CVE-2025-21042 (CVSS score: 8.8), an out-of-bounds write flaw in the "libimagecodec.quram.so" component that could allow remote attackers to execute arbitrary code, according to Palo Alto Networks Unit 42.

  3. LANDFALL Spyware Exploited Samsung Galaxy Zero-Day in Targeted Middle ...

    The exploitation of CVE-2025-21042 to distribute LANDFALL spyware illustrates the widening attack surface in mobile ecosystems. For Samsung Galaxy users in the Middle East, the campaign represents both a direct invasion of privacy and a notable evolution in cyber-espionage tactics. Vigilance, device…

  4. CVE-2025-21042 - Exploits & Severity - Feedly

    CVE-2025-21042 is a high-severity vulnerability identified in Samsung Mobile Devices, specifically involving an out-of-bounds write flaw in the component libimagecodec.quram.so.

  5. CVE-2025-21042 Security Vulnerability & Exploit Details

    The exploitability of CVE-2025-21042 depends on two key factors: attack complexity (the level of effort required to execute an exploit) and privileges required (the access level an attacker needs).