logo

A look at an Android ITW DNG exploit

ID: 23b760e6-6674-5653-af8f-7db47bd12441

STIX ID: report--23b760e6-6674-5653-af8f-7db47bd12441

Feed Name: Google Project Zero

Threat Score
85/100

Date Published: 2025-12-12

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

Between July 2024 and February 2025, crafted DNG images uploaded to VirusTotal (and observed in the wild) exploited a bounds/plane validation bug in the Quram image decoder used by Samsung's com.samsung.ipservice to achieve remote code execution; attackers used opcode-based heap primitives, ASLR bypass via crafted MapTable substitution tables, and a JOP chain to invoke system() and drop/run a spyware agent (payload staged as a polyglot DNG/ZIP). Samsung issued a fix in April 2025 and the issue was later tracked as CVE-2025-21042.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.