CVE-2025-21075

Published Nov 5, 2025

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-21075 is an out-of-bounds write vulnerability found in the `libimagecodec.quram.so` library. It allows remote attackers to access out-of-bounds memory. The vulnerability affects Android versions 13, 14, 15, and 16. Samsung addressed this vulnerability in their November 2025 Security Maintenance Release (SMR). The patch adds proper input validation to prevent out-of-bounds memory access. Users are advised to update their devices to SMR Nov-2025 Release 1 or later.

Description
Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Source
mobile.security@samsung.com
NVD status
Analyzed
Products
android

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-787

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

7

Configurations

References

Sources include official advisories and independent security research.