Samsung fixes Android 0-day that may have been used to spy on WhatsApp messages
ID: 3131410b-11ff-5c72-9338-eca948533277
STIX ID: report--3131410b-11ff-5c72-9338-eca948533277
Feed Name: The Register (Security)
Samsung patched a critical out-of-bounds write RCE in libimagecodec.quram.so (CVE-2025-21043) affecting Android 13–16 after reports of in-the-wild exploitation; vendors and researchers warn this flaw may have been chained with a WhatsApp vulnerability (CVE-2025-55177) and an Apple ImageIO bug (CVE-2025-43300) in highly targeted zero-click attacks against specific individuals, with Amnesty International and vendor advisories investigating possible commercial surveillanceware use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
