---
id: CVE-2025-21043
title: >-
  Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1
  allows remote attackers to execute arbitrary code.
summary: >-
  Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1
  allows remote attackers to execute arbitrary code.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-787
vendor: Samsung Mobile
product: Samsung Mobile Devices
affected:
  - devices (all versions)
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-10-02T03:55:43.979759Z'
exploited: true
exploitAvailable: true
published: '2025-09-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:59:17.893Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-21043'
references:
  - url: 'https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=09'
tags:
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
epss: 0.0214
epssPercentile: 0.81432
kev: true
kevDateAdded: '2025-10-02'
kevDueDate: '2025-10-23'
kevRansomware: false
ingestedAt: '2026-10-07T18:42:20.912Z'
---

## Overview

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

## Affected

- `devices (all versions)`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
