Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSamsung Android
OSSamsung13.014.015.016.0
CISA KEV — detailsi
- Vendori
- Samsung
- Producti
- Mobile Devices
- Added to KEVi
- October 2, 2025
- Remediation deadline (US Federal)i
- October 23, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.
Related vulnerabilities
Path Traversal w Samsung Galaxy Themes Service — dostęp do plików systemowych
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execu...
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Releas...
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inope...
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers...