LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-21042: Samsung Mobile Devices Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 10, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 1, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-21042 to its Known Exploited Vulnerabilities catalog on Nov 10, 2025, with a federal patch deadline of Dec 1, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.

CVE-2025-21042 is an out-of-bounds write vulnerability affecting Samsung mobile devices in the library libimagecodec.quram.so. According to CISA, this flaw could allow remote attackers to execute arbitrary code. For IT and security teams managing fleets of Samsung phones or tablets, the issue matters because successful exploitation can give an attacker control over the device, potentially leading to data access, persistence, or further network movement if the device is connected to corporate resources.

Public detail is limited to the CISA summary and the CWE classification; exact attack vectors, affected firmware builds, and severity metrics must be confirmed against the vendor advisory before prioritizing response.

How it works

The vulnerability is classified as CWE-787, an out-of-bounds write. In this class of flaw, a program writes data past the end (or before the beginning) of an allocated buffer. On Samsung mobile devices the affected component is libimagecodec.quram.so, which handles image decoding. When malformed or specially crafted image data is processed, the library can write outside its intended memory region.

An attacker who can deliver such data to the vulnerable library—commonly through a remote channel that causes the device to parse an image—may corrupt adjacent memory structures. That corruption can be leveraged to alter control flow and achieve arbitrary code execution in the context of the process that loads the library. No specific exploit mechanics, payload formats, or privilege levels beyond the CISA description are provided in the available facts; defenders should treat any remote image-processing path as a potential entry point until the vendor advisory clarifies the exact conditions.

Am I affected? How to find it in your systems

The vulnerability is reported against Samsung mobile devices. Typical environments include employee-owned or company-issued Galaxy phones and tablets that process images via system or third-party applications relying on the Quram image codec library.

Confirm exact affected versions and configurations solely against Samsung’s security advisory; do not rely on generic Android patch levels alone.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2025-21042. Follow Samsung’s official instructions for the security patch or firmware release that resolves the out-of-bounds write in libimagecodec.quram.so. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-managed services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

When immediate patching is not feasible, reduce exposure with compensating controls appropriate to the out-of-bounds write and remote-code-execution class.

These measures buy time but do not eliminate the underlying vulnerability; schedule patching as soon as operationally possible.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to device compromise and subsequent data exposure. Although ransomware use is not documented for this CVE, any successful exploitation could allow an attacker to exfiltrate credentials, messages, or files stored on the device. Organizations should review device logs, network traffic, and authentication records for signs of compromise. Individuals whose devices may have been affected can run a free exposure scan of their email addresses against known breach data sets to determine whether personal information has already appeared in public or underground collections. Containment, credential rotation, and full device re-imaging remain the recommended recovery steps when compromise is confirmed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSamsung · Mobile Devices
WeaknessCWE-787
Added to CISA KEVNov 10, 2025
Federal patch deadlineDec 1, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities