• News/
  • https://www.bleepingcomputer.com/news/security/samsung-patches-actively-exploited-zero-day-reported-by-whatsapp/

Samsung patches actively exploited zero-day reported by WhatsApp

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 12, 2025
·
Updated

Samsung has patched a remote code execution vulnerability that was exploited in zero-day attacks targeting its Android devices. Tracked as CVE-2025-21043, this critical security flaw affects Samsung devices running Android 13 or later and was reported by the security teams of Meta and WhatsApp on August 13. As Samsung explains in a recently updated advisory, this vulnerability was discovered in libimagecodec.quram.so (a closed-source image parsing library developed by Quramsoft that implements support for various image formats) and is caused by an out-of-bounds write weakness that allows attackers to execute malicious code on vulnerable devices remotely. "Out-of-bounds Write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code," Samsung says. "Samsung was notified that an exploit for this issue has existed in the wild." While Samsung didn't specify whether the attacks targeted only WhatsApp users with Samsung Android devices, other instant messengers that utilize the vulnerable image parsing library could also be potentially targeted using CVE-2025-21043 exploits. "As part of our proactive investigation into a highly targeted exploit over the summer (which resulted in our security advisory for iOS/MacOS WhatsApp users), we shared our findings with our industry peers, including Apple and Samsung," a Meta spokesperson told BleepingComputer. "Apple mitigated the relevant high-severity vulnerability (CVE-2025-43300) last mon...

Read full article

Affected Software

2 affected components
Samsung android=13
Quramsoft libimagecodec.quram.so
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerability is discussed in the article?

The article discusses a remote code execution vulnerability tracked as CVE-2025-21043.

2

How does this vulnerability affect Samsung devices?

This critical security flaw affects Samsung devices running Android 13 or later.

3

What type of attacks exploited this vulnerability?

The vulnerability was exploited in zero-day attacks targeting Samsung Android devices.

4

Who reported the vulnerability to Samsung?

The vulnerability was reported to Samsung by WhatsApp.

5

What is the key action taken by Samsung in response to this threat?

Samsung has patched the actively exploited zero-day vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203