CRITICAL
CVE-2025-21042
CVSS
9.8
KEV
Description
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
Summary dbcve.org
Out-of-bounds write vulnerability in Samsung's libimagecodec.quram.so library allows remote attackers to execute arbitrary code via a maliciously crafted image file processed by the library.
Mitigation
Apply the Samsung SMR (Security Maintenance Release) April-2025 update or later to receive the patched libimagecodec.quram.so library.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
33.17%
Probability of exploitation in next 30 days
98.3th percentile
References
https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=04
Vendor Advisory
https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/
Technical Description, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-21042
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.