Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryprivilege-escalation-methodidentity-authentication-vulnerability

Samsung Galaxy flaws exposed remote image RCE and SystemUI privilege escalation

Updated 12d agoFirst seen Jun 12, 20265 sources

Samsung disclosed multiple vulnerabilities affecting Galaxy devices, including remote code execution flaws in the proprietary Quram image codec and a separate improper access control bug in the Routines automation feature. CVE-2025-21042 and CVE-2025-21043 are out-of-bounds write issues in libimagecodec.quram.so that can be triggered by specially crafted images delivered through MMS, email attachments, messaging apps, or web content, potentially with little or no user interaction. Samsung said CVE-2025-21042 was fixed in the April 2025 Security Maintenance Release, while CVE-2025-21043 was addressed in the September 2025 SMR.

The disclosures revive longstanding concerns around Samsung’s proprietary image parsing stack, which Google Project Zero previously showed could be exploited through malformed Qmage images in a zero-click MMS chain that achieved code execution on a Galaxy Note 10+. Samsung also patched CVE-2025-21058, which allowed a local attacker on Android 15 and 16 devices to execute arbitrary code with SystemUI privileges via Galaxy Routines before versions 4.8.7.1 and 4.9.6.0. Separately, Google fixed Android framework flaw CVE-2025-32322 in the September 2025 Android Security Bulletin after it was found to let a malicious app bypass the MediaProjection consent dialog and silently capture screen content on Android 13 and 14.

Share:
Samsung Galaxy flaws exposed remote image RCE and SystemUI privilege escalation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Oct 9, 20259mo ago

Samsung discloses and fixes CVE-2025-21058 in Routines

Samsung disclosed CVE-2025-21058 in October 2025 and fixed the improper access control flaw in Galaxy Routines by adding authorization checks in versions 4.8.7.1 for Android 15 and 4.9.6.0 for Android 16.

Samsung Routines CVE-2025-21058: Brief Summary of Improper Access Control in Android 15 and 16 - ZeroPath Blog | ZeroPath
Sep 12, 202510mo ago

Samsung patches CVE-2025-21043 in September 2025 SMR

Samsung addressed CVE-2025-21043, a high-severity out-of-bounds write in the Quram image codec that could enable remote code execution through crafted images delivered by MMS, email, or web content, in its September 2025 Security Maintenance Release.

Samsung Quram Image Codec CVE-2025-21043 Out-of-Bounds Write: Brief Summary and Technical Review - ZeroPath Blog | ZeroPath

Samsung fixes CVE-2025-21042 in April 2025 SMR

Samsung addressed CVE-2025-21042, an out-of-bounds write in libimagecodec.quram.so that could enable remote code execution via crafted images, in the April 2025 Security Maintenance Release.

CVE-2025-21042 in Samsung libimagecodec.quram.so: Brief Summary of a Critical Out-of-Bounds Write Vulnerability - ZeroPath Blog | ZeroPath
Sep 5, 202510mo ago

Google fixes MediaProjection bypass in September 2025 bulletin

Google confirmed CVE-2025-32322 in the September 2025 Android Security Bulletin and fixed the MediaProjection consent-dialog bypass in security patch level 2025-09-05.

Android MediaProjection Screen Recording Bypass (CVE-2025-32322): Brief Summary and Technical Review - ZeroPath Blog | ZeroPath
Feb 24, 201511y ago

Samsung patches Qmage vulnerabilities under CVE-2020-8899

Samsung patched the reported Qmage codec flaws in May 2020, tracking them under CVE-2020-8899 and SVE-2020-16747.

MMS Exploit Part 1: Introduction to the Samsung Qmage Codec and Remote Attack Surface - Project Zero

Project Zero reports multiple Qmage flaws to Samsung

Mateusz Jurczyk reported numerous memory corruption vulnerabilities in Samsung’s Qmage codec to Samsung in January 2020 after analyzing the proprietary image format and its attack surface.

MMS Exploit Part 1: Introduction to the Samsung Qmage Codec and Remote Attack Surface - Project Zero

Qmage codec integrated into Samsung devices

Google Project Zero reported that Samsung’s proprietary Qmage image codec had been deeply integrated into Samsung Android devices through the Skia graphics stack since late 2014, creating a broad attack surface for image parsing.

MMS Exploit Part 1: Introduction to the Samsung Qmage Codec and Remote Attack Surface - Project Zero
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

22 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.