logo

Samsung fixed actively exploited zero-day

ID: d03d5850-cb10-5009-9e69-c64dcd8eaa36

STIX ID: report--d03d5850-cb10-5009-9e69-c64dcd8eaa36

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2025-09-12

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Samsung released a patch for an actively exploited Android remote code execution zero-day (CVE-2025-21043) — an out-of-bounds write in libimagecodec.quram.so — that was used in zero-click spyware attacks; WhatsApp and Meta reported the issue, WhatsApp issued threat notifications to potentially targeted users, and researchers linked related iOS/macOS and Apple zero-click flaws (CVE-2025-55177 and CVE-2025-43300) to an advanced, likely state-sponsored campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.