Loading HuntDB...

CVE-2025-21043

HIGH
Published 2025-09-12T07:21:51.025Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-21043. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
8.8
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score Metrics
Exploitability: N/A Impact: N/A

Attack Vector Metrics

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED

Impact Metrics

Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Description

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

Available Exploits

No exploits available for this CVE.

Related News

Samsung Fixes Image Parsing Vulnerability Exploited in Android Attacks

Samsung patched CVE-2025-21043, a critical flaw in its Android devices exploited in live attacks. Users urged to install September 2025 update.

HackRead 2025-09-14 22:17
Samsung Fixes Critical Zero-Day CVE-2025-21043 Exploited in Android Attacks

Samsung has released its monthly security updates for Android, including a fix for a security vulnerability that it said has been exploited in zero-day attacks. The vulnerability, CVE-2025-21043 (CVSS score: 8.8), concerns an out-of-bounds write that could re…

Internet 2025-09-12 15:16
Samsung fixed actively exploited zero-day

Samsung fixed the remote code execution flaw CVE-2025-21043 that was exploited in zero-day attacks against Android devices. Samsung addressed the remote code execution vulnerability, tracked as CVE-2025-21043, that was exploited in zero-day attacks against An…

Securityaffairs.com 2025-09-12 11:44

Affected Products

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

Affected Products (ENISA)

samsung mobile
samsung mobile devices

ENISA Scoring

CVSS Score (3.1)

8.8
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Score

0.100
probability

Data provided by ENISA EU Vulnerability Database. Last updated: September 13, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed HIGH

GHSA-h4h8-5cww-x7j2

Advisory Details

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

CVSS Scoring

CVSS Score

7.5

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Advisory provided by GitHub Security Advisory Database. Published: September 12, 2025, Modified: September 12, 2025

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

16 posts
Reddit 7 hours, 10 minutes ago
ContentByrkRahul
Exploit

Best VPNs for Samsung Galaxy Phones Samsung Galaxy phones face an unprecedented wave of security threats in 2025. Just this September, Samsung released emergency patches for **CVE-2025-21043**, a critical zero-day vulnerability with an 8.8 severity score that allowed remote attackers to execute malicious code on Galaxy devices running Android 13-16. …

1
1.0
View Original High Risk
Reddit 7 hours, 35 minutes ago
crstux
Exploit PoC

🔥 Top 10 Trending CVEs (18/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-9708](https://nvd.nist.gov/vuln/detail/CVE-2025-9708)** - 📝 A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. …

3
3.0
View Original High Risk
Reddit 9 hours, 17 minutes ago
_cybersecurity_

Samsung Security Flaw Exposes Galaxy Users to Remote Hacking **A newly discovered flaw might allow hackers to hijack Samsung devices remotely; users should update their phones immediately.** **Key Points:** - CVE-2025-21043 vulnerability allows remote code execution. - Updates are available for all Samsung handsets running Android 13 or later. - …

Reddit 1 day, 7 hours ago
crstux
Exploit PoC

🔥 Top 10 Trending CVEs (17/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-41249](https://nvd.nist.gov/vuln/detail/CVE-2025-41249)** - 📝 The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an …

2
2.0
View Original High Risk
Reddit 1 day, 23 hours ago
Planhub-ca
Exploit

Samsung urges Galaxy users to install September’s update after an actively exploited zero-day in the image codec was confirmed Samsung’s September Security Maintenance Release fixes a critical out-of-bounds write in the Quram image codec that allows remote code execution. The company says an exploit “has existed in the wild,” credits …

1
1.0
View Original High Risk
Reddit 2 days, 7 hours ago
crstux

🔥 Top 10 Trending CVEs (16/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-6202](https://nvd.nist.gov/vuln/detail/CVE-2025-6202)** - 📝 Vulnerability in SK Hynix DDR5 on x86 allows a local attacker to trigger Rowhammer bit flips impacting the Hardware Integrity and the systems security.This issue affects DDR5: DIMMs …

Reddit 2 days, 21 hours ago
TechnoHacks181
Exploit PoC

Resumen Estratégico Semanal: Zero-Day de Samsung, Apple MIE, HybridPetya y Ataque a NPM Esta semana, el enfoque se ha centrado en las vulnerabilidades de plataforma, las defensas a nivel de hardware y los ataques a la cadena de suministro, mostrando cómo los adversarios atacan la confianza y las relaciones empresariales. …

1
1.0
View Original High Risk
Reddit 2 days, 23 hours ago
Suspicious_Bug4112
Exploit

Samsung Fixes Critical Zero-Day Vulnerability in Android Devices **Date:** 15-Sep-25 Samsung has issued a security update to patch a critical zero-day vulnerability (CVE-2025-21043) affecting Android devices, which has been exploited to execute arbitrary code by remote attackers. The flaw exists in the libimagecodec.quram.so library, crucial for image processing on Samsung …

1
1.0
View Original High Risk
Reddit 3 days ago
_cybersecurity_
Exploit

Samsung Addresses Critical Zero-Day Vulnerability Affecting Android Users **Samsung's recent security update addresses a serious vulnerability exploited by spyware targeting Android devices.** **Key Points:** - CVE-2025-21043 has been identified as a high-severity flaw scored 8.8 on the CVSS scale. - The vulnerability allows remote code execution on affected devices, potentially …

3
1
5.0
View Original High Risk
Reddit 3 days, 7 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (15/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-52915](https://nvd.nist.gov/vuln/detail/CVE-2025-52915)** - 📝 K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. …

2
2.0
View Original High Risk

References

Published: 2025-09-12T07:21:51.025Z
Last Modified: 2025-09-13T03:55:36.334Z
Copied to clipboard!