CVE-2025-21075

Published Nov 5, 2025

Last updated 3 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-21075 is an out-of-bounds write vulnerability found in the `libimagecodec.quram.so` library. It allows remote attackers to access out-of-bounds memory. The vulnerability affects Android versions 13, 14, 15, and 16. Samsung addressed this vulnerability in their November 2025 Security Maintenance Release (SMR). The patch adds proper input validation to prevent out-of-bounds memory access. Users are advised to update their devices to SMR Nov-2025 Release 1 or later.

Description
Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Source
mobile.security@samsung.com
NVD status
Analyzed
Products
android

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-787

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.