A look at an Android ITW DNG exploit
ID: 23b760e6-6674-5653-af8f-7db47bd12441
STIX ID: report--23b760e6-6674-5653-af8f-7db47bd12441
Feed Name: Google Project Zero
Between July 2024 and February 2025, crafted DNG images uploaded to VirusTotal (and observed in the wild) exploited a bounds/plane validation bug in the Quram image decoder used by Samsung's com.samsung.ipservice to achieve remote code execution; attackers used opcode-based heap primitives, ASLR bypass via crafted MapTable substitution tables, and a JOP chain to invoke system() and drop/run a spyware agent (payload staged as a polyglot DNG/ZIP). Samsung issued a fix in April 2025 and the issue was later tracked as CVE-2025-21042.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
