CRITICAL

CVE-2025-21043

Samsung Android 2025-09-12 CVSS v3.1
CVSS
9.8
KEV

Description

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

Summary dbcve.org

An out-of-bounds write vulnerability exists in Samsung's libimagecodec.quram.so image codec library. The flaw allows remote attackers to achieve arbitrary code execution, likely by tricking users into processing specially crafted malicious image files that trigger the memory corruption.

Mitigation

Apply the SMR Sep-2025 Release 1 security update or later, which contains the patched version of libimagecodec.quram.so. Until patched, avoid processing untrusted image sources.

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

1.91%
Probability of exploitation in next 30 days
78.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE