• News/
  • https://www.zdnet.com/article/you-should-update-your-samsung-phone-asap-this-zero-day-flaw-just-got-patched/

You should update your Samsung phone ASAP - this zero-day flaw just got patched

ZDNet
·
Charlie Osborne
·
Published Sep 18, 2025
·
Updated

Follow ZDNET: Add us as a preferred source on Google. Samsung recently issued a patch to resolve a critical vulnerability impacting its Android smartphone users. All impacted phone models will receive the fix, which patches a vulnerability tracked as CVE-2025-21043. The security flaw, issued a critical base score of 8.8 by Samsung Mobile (a CNA), is described as an "out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code." Also: Your Android phone's most powerful security feature is hidden and off by default - turn it on now The critical vulnerability was privately disclosed by Meta and WhatsApp security teams on August 13, 2025. The South Korean tech giant was also informed that an exploit for this bug exists in the wild. Samsung's September security advisory states that CVE-2025-21043 impacts Android 13, 14, 15, and 16, the latter being the latest version of the operating system. While a full list of impacted handset models has not been released, smartphones running unpatched versions of Android will likely be vulnerable to the exploit, which could allow attackers to execute malicious code on a vulnerable handset. Developed by Quramsoft, libimagecodec.quram.so is an image parsing library used by apps to parse and decode image formats on Samsung devices. This isn't the first time a security issue has impacted image-related software on Samsung handsets, as with CVE-2020-8899, in which an unauthenticated a...

Read full article

Affected Software

4 affected components
Samsung android=13
Samsung android=14
Samsung android=15
Samsung android=16
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical zero-day vulnerability in Samsung's Android operating system that has been patched.

2

What models are affected by the vulnerability?

All Samsung Android smartphone models running versions 13, 14, 15, and 16 are affected by the vulnerability.

3

What should Samsung users do following this announcement?

Samsung users are urged to update their phones as soon as possible to apply the patch and secure their devices.

4

What implications does this zero-day flaw have for users?

The zero-day flaw exposes users to potential exploitation, making their devices vulnerable to attacks.

5

How did Samsung respond to the vulnerability?

Samsung issued a patch to resolve the critical vulnerability, ensuring that all affected devices receive the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203