Skip to content

CVE-2025-21042: Samsung Galaxy Zero

Socradar November 11, 2025

A critical security vulnerability affecting Samsung Galaxy devices, tracked as CVE-2025-21042, has been confirmed as actively exploited and listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

Recently, the vulnerability has been linked to a sophisticated spyware campaign, LANDFALL, which used malicious image files to compromise targeted Samsung Galaxy models through apps such as WhatsApp.

This blog provides a detailed examination of CVE-2025-21042, how the exploitation occurred, which devices were affected, and what mitigations users and organizations should implement.

CVE-2025-21042 (CVSS 9.8) is a critical out-of-bounds write vulnerability located in Samsung’s libimagecodec.quram.so library, responsible for image decoding on Samsung mobile devices.

This flaw allows data to be written outside its intended memory boundaries. The vulnerability is remotely exploitable and can be triggered through a specially crafted image file, allowing Remote Code Execution (RCE) and control over the affected device.

Samsung initially addressed the issue in its April 2025 Security Maintenance Release (SMR) . But, the devices that have not installed this update remain vulnerable. Because the flaw resides in a central image library, any application relying on it to process untrusted images may serve as an attack vector.

CISA has added CVE-2025-21042 to its Known Exploited Vulnerabilities (KEV) catalog following verified reports of active exploitation.

According to CISA’s guidance, all Federal Civilian Executive Branch (FCEB) agencies are required to apply Samsung’s recommended mitigations or discontinue use of unpatched devices by December 1, 2025 .

This directive underscores the severity of the flaw and serves as a transition point to examine how the vulnerability was leveraged in the LANDFALL spyware campaign, which revealed the full impact of this exploitation.

Researchers discovered the LANDFALL spyware family, which leveraged CVE-2025-21042 within a complex exploit chain that specifically targeted Samsung Galaxy smartphones.

Attackers crafted malformed DNG image files (Digital Negative format) containing an embedded ZIP archive appended to the image data. When a vulnerable device processed these files through libimagecodec.quram.so, the exploit executed and extracted malicious components from the archive, including a loader file named b.so , internally referenced as “Bridge Head.”

Evidence strongly indicates that the spyware spread through zero-click or near-zero-click delivery via WhatsApp . VirusTotal samples, labeled with names such as “WhatsApp Image” and WA0000 , appeared between July 2024 and early 2025, confirming exploitation months before public disclosure.

Once installed, LANDFALL granted attackers extensive surveillance capabilities, including audio and call recording, geolocation tracking, photo and message exfiltration, and SELinux policy manipulation for persistence and privilege escalation.

The LANDFALL spyware was engineered for flagship Samsung devices. Debug strings within its loader referenced Galaxy S22 , S23 , S24 , Z Fold4 , and Z Flip4 models. Telemetry and sample submissions confirm that these flagship models were the primary focus of exploitation efforts.

Telemetry and VirusTotal sample data suggest that potential targets include Iraq, Iran, Turkey, and Morocco , aligning with patterns typical of regional surveillance operations.

Researchers observed that the campaign’s infrastructure and methodology mirror those used by commercial spyware vendors operating in the Middle East, although no definitive attribution has been established.

The spyware’s Command and Control (C2) infrastructure used deceptive domains hosted on European servers, and activity persisted from mid-2024 through late 2025, reflecting a deliberate, sustained espionage campaign rather than opportunistic attacks.

CVE-2025-21042 exemplifies an emerging trend in mobile exploitation: targeting complex media parsers that automatically handle images in messaging and gallery applications. Between 2024 and 2025, several related vulnerabilities reinforced this pattern:

Researchers indicate that DNG-based exploits have become a preferred delivery vector for spyware, given that image files are widely shared and often processed without user interaction.

Gain proactive insight with SOCRadar’s Cyber Threat Intelligence (CTI) module , designed to keep you ahead of emerging vulnerabilities like CVE-2025-21042. With real-time vulnerability intelligence, exploit tracking, and correlation across global threat feeds, it enables your security team to prioritize patching and mitigate risks faster.

Additionally, integrated Attack Surface Management (ASM) capabilities provide continuous visibility into exposed assets, helping you discover, assess, and secure your digital footprint before threat actors strike – all within a unified intelligence platform.

Although Samsung resolved this vulnerability in April 2025, unpatched devices remain exposed. Users and organizations should implement the following actions:

For individual users:

For enterprises and government agencies:

Based on Unit 42’s analysis of the LANDFALL spyware campaign exploiting CVE-2025-21042, the following indicators of compromise (IOCs) have been identified. Security teams are advised to monitor for any communication with the listed IP addresses or domains and to block or flag any file hashes matching these indicators.

Extracted Entities

Attack Types (2)

Companies (1)

Countries (4)

Malware (1)