
CVE-2025-21042
A critical vulnerability in Samsung’s image-processing library
libimagecodec.quram.so — used on Galaxy Android devices.
🧩 It’s an out-of-bounds write flaw triggered when parsing malicious image files (like DNG).
📸 A crafted image can let attackers run arbitrary code remotely on the device.
“Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.” — NVD Summary
| Metric | Value |
|---|---|
| CVSS v3.1 Score | 💣 9.8 / 10 (CRITICAL) |
| Attack Vector | 🌐 Network |
| Privileges Required | ❌ None |
| User Interaction | ⚙️ None (Zero-click possible) |
👉 Translation: an attacker could compromise your phone just by sending you an image — no taps needed.
Used by spyware operators to gain full control of affected devices — including camera, mic, and data exfiltration.
📱 Samsung Android devices running firmware before ➡️ SMR Apr-2025 Release 1
If your device hasn’t received that patch — you’re still vulnerable.
✅ Update now: Go to Settings → Software Update → Download and Install Make sure your security patch level is April 2025 or later.
🚫 Avoid:
🏢 For enterprises: