• News/
  • https://www.theregister.com/2025/09/12/samsung_fixes_android_0day/

Samsung fixes Android 0-day that may have been used to spy on WhatsApp messages

The Register
·
Jessica Lyons
·
Published Sep 12, 2025
·
Updated

Samsung has fixed a critical flaw that affects its Android devices - but not before attackers found and exploited the bug, which could allow remote code execution on affected devices. The vulnerability, tracked as CVE-2025-21043, affects Android OS versions 13, 14, 15, and 16. It's due to an out-of-bounds write vulnerability in libimagecodec.quram.so, a parsing library used to process image formats on Samsung devices, which remote attackers can abuse to execute malicious code. "Samsung was notified that an exploit for this issue has existed in the wild," the electronics giant noted in its September security update. The Meta and WhatsApp security teams found the flaw and reported it to Samsung on August 13. Apps that process images on Samsung kit, potentially including WhatsApp, may trigger this library, but Samsung didn't name specific apps. The warning is interesting, because Meta shortly thereafter issued a security advisory warning that attackers may have chained a WhatsApp bug with an Apple OS-level flaw in highly targeted attacks. The WhatsApp August security update included a fix for CVE-2025-55177 that, as Meta explained, "could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target's device." That security advisory went on to say, "We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted use...

Read full article

Affected Software

0 affected components

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical Android 0-day vulnerability in Samsung devices that has been exploited.

2

What security implications are discussed in the article?

The vulnerability may have been used by attackers to spy on WhatsApp messages through remote code execution.

3

What specific vulnerability is mentioned in the article?

The vulnerability is tracked as CVE-2025-21043 and affects multiple Android OS versions.

4

Which Android OS versions are affected by this vulnerability?

The vulnerability affects Android OS versions 13, 14, 15, and 16.

5

Has Samsung released a fix for the vulnerability?

Yes, Samsung has issued a fix for the critical flaw affecting its Android devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203