A threat actor exploited a zero-day vulnerability in Samsung’s Android image processing library to deploy a previously unknown spyware called 'LandFall' using malicious images sent over WhatsApp. The security issue was patched this year in April, but researchers found evidence that the LandFall operation was active since at least July 2024, and targeted select Samsung Galaxy users in the Middle East. Identified as CVE-2025-21042, the zero-day is an out-of-bounds write in libimagecodec.quram.so and has a critical severity rating. A remote attacker successfully exploiting it can execute arbitrary code on a target device. According to researchers at Palo Alto Networks’ Unit 42, the LandFall spyware is likely a commercial surveillance framework used in targeted intrusions. The attacks begin with the delivery of a malformed .DNG raw image format with a .ZIP archive appended towards the end of the file. Unit 42 researchers retrieved and examined samples that were submitted to the VirusTotal scanning platform starting July 23, 2024, indicating WhatsApp as the delivery channel, based on the filenames used. From a technical perspective, the DNGs embed two main components: a loader (b.so) that can retrieve and load additional modules, and a SELinux policy manipulator (l.so), which modifies security settings on the device to elevate permissions and establish persistence. According to the researchers, LandFall can fingerprint devices based on hardware and SIM IDs (IMEI, IMSI, the SIM ca...
New LandFall spyware exploited Samsung zero-day via WhatsApp messages
BleepingComputer
·Bill Toulas
·Published Nov 7, 2025
·Updated
Affected Software
2 affected components
Samsung Android image processing library
Samsung Galaxy
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the LandFall spyware that exploits a zero-day vulnerability in Samsung's Android image processing library via WhatsApp.
2
What security implications are discussed?
The article highlights the risk of malicious images being used to deliver spyware to Samsung device users through WhatsApp.
3
What products or software are affected?
The affected products include Samsung's Android image processing library and Samsung Galaxy devices.
4
How was the spyware delivered to victims?
The LandFall spyware was delivered through malicious images sent over WhatsApp messages.
5
Was the vulnerability patched, and if so, when?
Yes, the security issue was patched, although the specific date of the patch is not mentioned in the article.