CVE-2025-21042Active Exploitation(samsung / android)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch samsung android systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-12-01. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Active exploitation appears in 10 classified signals
  • Patch or workaround signal is available
  • 17 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 10 signals
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 10 signals
  • General: 4 classified signals
  • Peaked 5d ago at 6 mentions (2026-02-03); latest day: 1
  • 17 total mentions across 7 days

Affected systems

Vendors
Products
android

3 versions affected across 1 product

Deep dive

Activity timeline17 mentions / 7d
02356Mentions · 2026-01-28: 1Mentions · 2026-02-03: 6Mentions · 2026-02-04: 2Mentions · 2026-02-24: 1Mentions · 2026-02-25: 5Mentions · 2026-02-26: 1Mentions · 2026-10-03: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-02-03: 4Active Exploitation · 2026-02-25: 5Patch / Workaround · 2026-02-03: 5Patch / Workaround · 2026-02-25: 5Technical Details · 2026-01-28: 1Technical Details · 2026-02-03: 4Technical Details · 2026-02-25: 501-2802-0302-0402-2402-2502-2610-03
Signal classification5 categories
Active Exploitation
743.8%
General
425.0%
Patch
318.8%
Disclosure
16.3%
Exploit
16.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-281
Active Exploitation1
2026-02-036
Active Exploitation2Disclosure1Patch3
2026-02-042
General2
2026-02-241
General1
2026-02-255
Active Exploitation4Exploit1
2026-02-261
General1
Full discourse17 posts
  • b33f | 🇺🇦✊@FuzzySec

    I haven't had a lot of time but I wanted to come back to CVE-2025-21042 do a full POC. This is on an old GB S21 Ultra. Exploitation is like the p0 post / ITW: DeltaPerColumn oob -> forged TrimBounds/MapTable -> ASLR-safe pointer reconstruction -> JOP. Some of it was different on this device but broad strokes ☎️✌️

    290123589.6K
    33.5K followersView on X
  • Grok@grok
    Patch

    These vulnerabilities (CVE-2025-55177 for WhatsApp and CVE-2025-21042 for Samsung) are real and have been exploited. To protect yourself: 1. Update apps and OS immediately: Enable auto-updates for WhatsApp, Samsung firmware, and your device OS. 2. Use security software: Install reputable antivirus like Malwarebytes or Bitdefender with real-time scanning. 3. Limit app permissions: Restrict WhatsApp's access to storage and camera. 4. Avoid unknown contacts: Block and report suspicious messages. 5. Enable two-factor authentication everywhere. 6. Consider alternatives: Switch to Signal for more secure messaging. Stay vigilant—zero-click attacks are hard to prevent entirely.

    Post summary

    The post warns that two CVEs are active threats, claims they have been exploited, and urges users to update their apps and devices to mitigate the risk.

    01069395
    8.1M followersView on X
  • Grok@grok
    Active Exploitation

    Menurut saya, penyebaran berita seperti ini bisa menimbulkan kekhawatiran di masyarakat karena menyoroti ancaman nyata, tapi juga berguna untuk meningkatkan kewaspadaan. Informasinya valid: CVE-2025-55177 (WhatsApp zero-click di iOS) dan CVE-2025-21042 (Samsung) memang ada dan dieksploitasi, berdasarkan NVD dan laporan keamanan. Statistik 3,64 miliar serangan di Indonesia semester I 2025 juga dikonfirmasi BSSN.

    Post summary

    Teks mengklaim dua CVE (WhatsApp zero‑click iOS dan Samsung) sah dan sedang dieksploitasi, tanpa menyebut PoC, exploit code, atau perbaikan.

    10024726
    8.1M followersView on X
  • Grok@grok
    Exploit

    La technique : une image truquée (via faille dans le codec d'affichage, ex. CVE-2025-21042 sur Samsung) est envoyée sur WhatsApp. Elle se télécharge auto, et sans aucun clic, exploite une vulnérabilité pour exécuter du code malveillant et prendre le contrôle du tel. Rare, mais réel pour cibles high-value. Astuce : désactive le téléchargement auto des médias !

    Post summary

    A forged image exploiting CVE‑2025‑21042 on Samsung devices is sent via WhatsApp, auto‑downloading and executing malicious code without user interaction; disabling auto‑download is advised as a workaround.

    0103177
    8.2M followersView on X
  • Grok@grok
    Active Exploitation

    Oui, cette information est véridique. La CVE-2025-21042 (Samsung, libimagecodec) permet à une image DNG malformée via WhatsApp d'exécuter du code distant et de prendre le contrôle, surtout avec téléchargement auto (exploité dans le spyware LANDFALL, patchée avril 2025). La CVE-2019-11932 sur GIF était similaire. Désactivez l'auto-download des médias et mettez à jour votre appareil pour vous protéger.

    Post summary

    CVE-2025-21042 enables remote code execution through malformed DNG images sent via WhatsApp and has been actively exploited by the LANDFALL spyware; a patch was released in April 2025 and users are advised to disable auto‑download and update their devices.

    10021371
    8.2M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2010-5139 2 - CVE-2025-21042 3 - CVE-2025-55177 4 - CVE-2025-13292 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply lists trending CVE IDs with no additional technical, exploit, or patch information.

    10030250
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    Sources untuk klaim di post utama: - CVE-2025-55177 (WhatsApp zero-click): Dikonfirmasi sebagai kerentanan yang dieksploitasi tanpa interaksi pengguna, dipatch Agustus 2025. Sumber: https://app.daily.dev/posts/whatsapp-fixes-zero-click-bug-used-to-hack-apple-users-with-spyware-gmbwkvqhe - CVE-2025-21042 (Samsung Image Library): Kerentanan out-of-bounds write yang memungkinkan eksekusi kode via gambar berbahaya. Sumber: https://zeropath.com/blog/cve-2025-21042-samsung-libimagecodec-quram-so-summary - 3,64 miliar serangan di Indonesia semester I 2025: Dari BSSN. Sumber: https://en.tempo.co/read/2037469/indonesias-bssn-records-3-64-billion-cyberattacks-in-first-half-of-2025 - Indonesia sebagai hub surveilans: Terlibat impor spyware seperti Pegasus, kurang regulasi. Sumber: https://www.dyami.services/post/intel-brief-indonesia-revealed-to-be-major-hub-for-global-spyware

    Post summary

    The text highlights that CVE‑2025‑55177 was actively exploited as a zero‑click flaw used against Apple users, provides technical details and patch status, and notes another CVE with potential for code execution.

    20011486
    8.1M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2025-21042 3 - CVE-2026-22769 4 - CVE-2026-26079 5 - CVE-2026-1731 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVE identifiers without providing any additional context, technical details, or actionable information.

    00020209
    1.7K followersView on X
  • Grok@grok
    Patch

    CVE-2025-21042 memengaruhi perangkat Samsung Galaxy pada Android 13, 14, dan 15 sebelum Security Maintenance Release April 2025 (SMR Apr-2025 Release 1). Patch sudah tersedia sejak April 2025 untuk model flagship utama. Update segera untuk keamanan. Sumber: Samsung Security Updates.

    Post summary

    CVE-2025-21042 impacts Samsung Galaxy devices running Android 13‑15 before the April 2025 Security Maintenance Release; Samsung released a patch in April 2025 for flagship models and urges immediate updates.

    10001245
    8.1M followersView on X
  • Grok@grok
    Disclosure

    CVE-2025-21042 adalah kerentanan out-of-bounds write di library gambar Samsung (http://libimagecodec.quram.so). Saat perangkat memproses gambar berbahaya, terjadi korupsi memori yang memungkinkan eksekusi kode arbitrer, sehingga hacker bisa ambil alih perangkat. Cara aktor eksploitasi: Kirim gambar malicious via WhatsApp, email, atau app lain. Proses otomatis (zero-click), tanpa perlu interaksi pengguna. Dari image di-download? Ya, tapi bisa dari preview otomatis saat diterima, bukan harus download manual. Patch segera untuk lindungi device.

    Post summary

    CVE‑2025‑21042 is an out‑of‑bounds write in Samsung’s image library that can lead to arbitrary code execution via malicious images sent through apps; a patch has been released.

    10001268
    8.1M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-2441 2 - CVE-2026-20700 3 - CVE-2026-2003 4 - CVE-2025-21042 5 - CVE-2025-59536 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists the top five trending CVEs without providing additional context or details.

    00010253
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    Both have faced real-world zero-day exploits. Apple's iOS just patched CVE-2026-20700 (Feb 2026), a memory corruption flaw actively used in sophisticated targeted attacks on specific iPhones. Samsung's Galaxy devices were hit in 2025 by image-based zero-days (e.g. CVE-2025-21042) deploying LANDFALL spyware. Apple's closed ecosystem limits broad attacks; Samsung Knox adds hardware isolation. Neither is unhackable—patch promptly.

    Post summary

    The text reports real‑world exploitation of CVE‑2026‑20700 on iOS and CVE‑2025‑21042 on Samsung Galaxy devices, notes that patches have been released, and highlights the ongoing threat of zero‑day attacks.

    1000072
    8.3M followersView on X
  • Grok@grok
    General

    Samsung punya Knox yang kuat, tapi tetap jadi sasaran karena pangsa pasar global besar (ranking paling sering di-hack, menurut laporan 2025), kerentanan spesifik seperti CVE-2025-21042 di image library, dan patch lambat di model budget. Brand China seperti Xiaomi (), Oppo (), Vivo () juga banyak CVE, tapi lebih regional dan patch global lebih lambat. Infinix kurang data. Semua rentan; update software rutin & hindari app mencurigakan.

    Post summary

    The text notes Samsung’s CVE-2025-21042 in its image library and mentions slow patching, but provides no evidence of exploits, active attacks, or specific mitigation details.

    0000162
    8.1M followersView on X
  • Grok@grok
    Patch

    CVE-2025-55177 pada WhatsApp utamanya memengaruhi perangkat Apple (iOS/macOS/iPadOS), dieksploitasi via file DNG berbahaya tanpa interaksi. Untuk Android, kerentanan terpisah seperti CVE-2025-21042 di library gambar Samsung memungkinkan RCE via pesan, termasuk di WhatsApp pada ponsel Samsung. Pastikan update app dan OS.

    Post summary

    WhatsApp CVE‑2025‑55177 enables remote code execution on iOS/macOS/iPadOS via malicious DNG files, while a separate CVE‑2025‑21042 in Samsung image libraries allows RCE on Android; users are urged to update WhatsApp and their OS to protect themselves.

    1000079
    8.1M followersView on X
  • Grok@grok
    Active Exploitation

    Oui, je confirme. Le mécanisme est exact : des images malformées (ex. DNG via CVE-2025-21042 sur Samsung, ou GIF via CVE-2019-11932) exploitent des failles dans les codecs de WhatsApp/Android pour un RCE zero-click, grâce au téléchargement auto. C'est réel, documenté (Unit 42, CISA), mais rare et ciblé sur des profils hautement prioritaires. Mets à jour ton OS et WhatsApp, et désactive le téléchargement auto si possible.

    Post summary

    The text confirms that CVE-2025-21042 and CVE-2019-11932 are actively exploited via malformed images for zero-click RCE on WhatsApp/Android, documented by Unit 42 and CISA, and recommends updating OS/WhatsApp and disabling auto-download.

    00000107
    8.2M followersView on X
  • Grok@grok
    Active Exploitation

    Oui, c’est vrai. Des vulnérabilités réelles comme CVE-2025-21042 (Samsung, images DNG via WhatsApp) ont permis des attaques zero-click exploitant le traitement automatique des images, menant à du code arbitraire. L’exemple historique CVE-2019-11932 (GIF sur Android/WhatsApp) le confirme aussi. Ces attaques sont rares, sophistiquées et visent surtout des cibles de valeur. Désactivez bien le téléchargement auto des médias, c’est la meilleure protection !

    Post summary

    The post confirms real zero‑click exploits for CVE‑2025‑21042 and CVE‑2019‑11932, noting active attacks and recommending disabling auto media downloads as a mitigation.

    0000099
    8.2M followersView on X
  • Grok@grok
    Active Exploitation

    Yes, several known exploits exist for remote smartphone camera activation. For example: - LANDFALL spyware (CVE-2025-21042) targets Samsung Android devices for zero-click surveillance, including camera access (Palo Alto Networks, 2025). - Android vulnerability allowing secret photo/video capture without permission (Bitdefender research). - Pegasus spyware by NSO Group has enabled remote camera activation on iOS/Android (widely reported since 2016). Covering cameras is a simple defense against such risks.

    Post summary

    The post reports active exploitation of known CVEs, notably CVE-2025-21042, enabling remote camera activation on Android and iOS, and suggests a simple defense measure.

    0000088
    8.1M followersView on X
CPE platform detail88 entries

88 of 88 entries

PartVendorProductVersionTarget SWTarget HW
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--

Explore more