Samsung has patched a remote code execution vulnerability that was exploited in zero-day attacks targeting its Android devices. Tracked as CVE-2025-21043, this critical security flaw affects Samsung devices running Android 13 or later and was reported by the security teams of Meta and WhatsApp on August 13. As Samsung explains in a recently updated advisory, this vulnerability was discovered in libimagecodec.quram.so (a closed-source image parsing library developed by Quramsoft that implements support for various image formats) and is caused by an out-of-bounds write weakness that allows attackers to execute malicious code on vulnerable devices remotely. "Out-of-bounds Write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code," Samsung says. "Samsung was notified that an exploit for this issue has existed in the wild." While Samsung didn't specify whether the attacks targeted only WhatsApp users with Samsung Android devices, other instant messengers that utilize the vulnerable image parsing library could also be potentially targeted using CVE-2025-21043 exploits. "As part of our proactive investigation into a highly targeted exploit over the summer (which resulted in our security advisory for iOS/MacOS WhatsApp users), we shared our findings with our industry peers, including Apple and Samsung," a Meta spokesperson told BleepingComputer. "Apple mitigated the relevant high-severity vulnerability (CVE-2025-43300) last mon...
Samsung patches actively exploited zero-day reported by WhatsApp
BleepingComputer
·Sergiu Gatlan
·Published Sep 12, 2025
·Updated
Affected Software
2 affected components
Samsung android=13
Quramsoft libimagecodec.quram.so
Frequently Asked Questions
1
What vulnerability is discussed in the article?
The article discusses a remote code execution vulnerability tracked as CVE-2025-21043.
2
How does this vulnerability affect Samsung devices?
This critical security flaw affects Samsung devices running Android 13 or later.
3
What type of attacks exploited this vulnerability?
The vulnerability was exploited in zero-day attacks targeting Samsung Android devices.
4
Who reported the vulnerability to Samsung?
The vulnerability was reported to Samsung by WhatsApp.
5
What is the key action taken by Samsung in response to this threat?
Samsung has patched the actively exploited zero-day vulnerability.