Skip to main content
Mallory
CriticalCISA KEVExploited in the wildPublic exploit

Samsung libimagecodec.quram.so Out-of-Bounds Write RCE

IdentifiersCVE-2025-21042CWE-787· Out-of-bounds Write

CVE-2025-21042 is an out-of-bounds write vulnerability in Samsung's image-processing library libimagecodec.quram.so, used on Samsung Galaxy devices. The flaw is triggered during parsing of crafted TIFF/DNG image content and can lead to memory corruption and arbitrary code execution. Reporting in the provided content indicates the bug was exploited as a zero-day to deliver the LANDFALL Android spyware family, with malformed DNG images carrying an appended ZIP archive used to extract and load malicious shared objects after exploitation. Samsung patched the issue in its April 2025 security release.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows remote code execution on the target Samsung device in the context of the vulnerable image-processing path. In observed in-the-wild activity, the vulnerability was used to deploy LANDFALL spyware, enabling extensive surveillance capabilities including collection of photos, contacts, SMS/messages, call logs, files, microphone and call recordings, location tracking, and follow-on payload execution. The content also indicates attackers used SELinux policy manipulation post-exploitation to obtain elevated permissions and persistence, resulting in effective full device compromise for targeted victims.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by limiting use of untrusted or unnecessary image-ingestion paths on affected Samsung devices, especially messaging-driven delivery of TIFF/DNG content. Monitor for suspicious DNG/TIFF files and related forensic indicators, review mobile threat telemetry for exploitation attempts or LANDFALL-related activity, and restrict high-risk users' exposure to unsolicited media over messaging platforms where operationally feasible. These are compensating controls only; the provided content does not describe a complete vendor-supported workaround short of patching.

Remediation

Patch, then assume compromise.

Apply Samsung's April 2025 security update or any later security maintenance release that includes the fix for CVE-2025-21042. More generally, ensure affected Samsung Galaxy devices are updated to the latest available vendor firmware/security patch level. Organizations should prioritize patching because the vulnerability was exploited in the wild and later added to CISA's Known Exploited Vulnerabilities catalog.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.

VALID 0 / 2 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Samsung ElectronicsAndroidoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence7

Every observed campaign linking this CVE to a named adversary.

Associated malware11

Malware families riding this exploit, with evidence and IOCs.

Detection signatures2

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity105

Community discussion across Reddit, Mastodon, and other social sources.