logo

Samsung fixes Android 0-day that may have been used to spy on WhatsApp messages

ID: 3131410b-11ff-5c72-9338-eca948533277

STIX ID: report--3131410b-11ff-5c72-9338-eca948533277

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-09-12

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Samsung patched a critical out-of-bounds write RCE in libimagecodec.quram.so (CVE-2025-21043) affecting Android 13–16 after reports of in-the-wild exploitation; vendors and researchers warn this flaw may have been chained with a WhatsApp vulnerability (CVE-2025-55177) and an Apple ImageIO bug (CVE-2025-43300) in highly targeted zero-click attacks against specific individuals, with Amnesty International and vendor advisories investigating possible commercial surveillanceware use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.