Saturday, 13 September, 2025
Samsung Fixes Critical Android Zero-Day CVE-2025-21043 Exploited in the Wild

Samsung has patched a critical zero-day vulnerability (CVE-2025-21043) in its September 2025 security update. The flaw is an “out-of-bounds write” in an image parsing library (libimagecodec.quram.so) that could allow remote code execution on Android 13–16 devices. It was privately reported on August 13, and Samsung confirmed the exploit is already being used in real attacks.
Read full story at The Hacker News