Samsung image library flaw used to deliver LANDFALL spyware
Case score 68
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 68
- Main story score
- 63
- Related evidence lift
- +5 / 20
- Contributing updates
- 2
- Context updates
- 2
- Vulnerability Defines the Samsung image-processing zero-day exploited before patching and anchors the Case. main
- Malware Activity Supplies direct evidence of malicious DNG delivery, persistence, and surveillance tooling used by LandFall. contributes
- Campaign Provides the LandFall campaign context, WhatsApp DNG delivery path, and spyware objective tied to CVE-2025-21042. contributes
- Public Sector Action Shows federal remediation pressure after CISA added CVE-2025-21042 to KEV and set a deadline. context
Overview
Latest development Open development history Palo Alto Networks discloses Landfall spyware on Samsung Galaxy phones Palo Alto Networks identified Landfall as an Android spyware campaign that exploited CVE-2025-21042 in a Samsung image processing library to achieve remote code execution, likely by delivering a specially crafted DNG image through WhatsApp in a zero-click exploit. The campaign targeted Samsung Galaxy S22, S23, S24, Z Fold4, and Z Flip4 phones, with Palo Alto Networks tracking the threat actor as CL-UNK-1054 and noting malicious DNG samples tied to individuals in Iran, Iraq, Turkey, and Morocco.
-
CISA adds CVE-2025-21042 after LandFall spyware campaign against Samsung devices
CISA adds CVE-2025-21042 to the KEV catalog and requires federal agencies to apply vendor mitigations by December 1 or discontinue use if mitigations are unavailable. Palo Alto Networks says the out-of-bounds write flaw CVE-2025-21042, with a CVSS score of 9.8, was patched by Samsung in April and had been used since mid-2024 in a LandFall spyware campaign that embedded malicious DNG image files sent through WhatsApp to targets. The campaign is described as targeting victims in the Middle East and enabling covert surveillance, including microphone recording, location tracking, and collection of photos, contacts, and call logs, with possible zero-click remote code execution.
-
Unit 42 details LandFall spyware and CVE-2025-21042 exploitation
Palo Alto Networks Unit 42 described LandFall as spyware delivered through malicious WhatsApp images that exploited CVE-2025-21042 in Samsung’s Android image processing library to run code on select Galaxy devices, with activity active since at least July 2024 and targeting users in the Middle East. The analysis also linked the campaign to a malformed .DNG payload with appended .ZIP content, loader components such as b.so and l.so, device fingerprinting, persistence, and spying functions, while attribution to a known vendor or threat group remained unconfirmed.
-
Samsung patches CVE-2025-21043 in SMR Sep-2025 Release 1
Samsung updated its advisory and released SMR Sep-2025 Release 1 for CVE-2025-21043, fixing the out-of-bounds write in libimagecodec.quram.so on Samsung devices running Android 13 or later. Samsung said the vulnerability allowed remote attackers to execute arbitrary code and that an exploit for the issue had existed in the wild, confirming active zero-day abuse against vulnerable Samsung Android devices.
-
Meta and WhatsApp report CVE-2025-21043 in Samsung Android devices
Meta and WhatsApp security teams reported CVE-2025-21043 to Samsung on August 13 after identifying a critical remote code execution flaw in libimagecodec.quram.so on Samsung devices running Android 13 or later. The issue is an out-of-bounds write in a closed-source image parsing library developed by Quramsoft and could let remote attackers execute arbitrary code on affected Samsung Android devices.