• News/
  • https://www.zdnet.com/article/update-your-samsung-phone-asap-to-patch-this-zero-day-flaw-exploited-in-the-wild/

Update your Samsung phone ASAP to patch this zero-day flaw exploited in the wild

ZDNet
·
Charlie Osborne
·
Published Sep 17, 2025
·
Updated

Follow ZDNET: Add us as a preferred source on Google. Samsung has issued a patch to resolve a critical vulnerability impacting its Android smartphone users. All impacted phone models will receive the fix, which patches a vulnerability tracked as CVE-2025-21043. The security flaw, issued a critical base score of 8.8 by Samsung Mobile (a CNA), is described as an "out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code." Also: Your Android phone's most powerful security feature is hidden and off by default - turn it on now The critical vulnerability was privately disclosed by Meta and WhatsApp security teams on August 13, 2025. The South Korean tech giant was also informed that an exploit for this bug exists in the wild. Samsung's September security advisory states that CVE-2025-21043 impacts Android 13, 14, 15, and 16, the latter being the latest version of the operating system. While a full list of impacted handset models has not been released, smartphones running unpatched versions of Android will likely be vulnerable to the exploit, which could allow attackers to execute malicious code on a vulnerable handset. Developed by Quramsoft, libimagecodec.quram.so is an image parsing library used by apps to parse and decode image formats on Samsung devices. This isn't the first time a security issue has impacted image-related software on Samsung handsets, as with CVE-2020-8899, in which an unauthenticated attack...

Read full article

Affected Software

4 affected components
Samsung Android=13
Samsung Android=14
Samsung Android=15
Samsung Android=16
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical zero-day vulnerability in Samsung Android smartphones that has been exploited in the wild and the urgent need for users to update their devices.

2

What security implications are discussed?

The article highlights the potential risk of unauthorized access and data breaches due to the exploitation of the zero-day flaw.

3

What products or software are affected?

The affected products include Samsung smartphones running Android versions 13, 14, 15, and 16.

4

How should Samsung users protect themselves from this vulnerability?

Samsung users are advised to immediately update their devices to the latest software version to patch the critical vulnerability.

5

Are all Samsung phone models impacted by this vulnerability?

Yes, all impacted Samsung phone models are set to receive the patch to address the zero-day vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Update your Samsung phone ASAP to patch this zero-day flaw exploited in the wild - SecAlerts