Skip to main content
Cyber Week Sale - Get 40% off Vantage
Published loading...Updated

Samsung phones under threat from this dangerous new spyware cyberattack - here's how to stay safe

The zero-day flaw CVE-2025-21042 was exploited in targeted Middle East attacks since July 2024, affecting multiple Galaxy models before Samsung patched it in April 2025.

  • CISA added CVE-2025-21042 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure Samsung devices within three weeks, until December 1.
  • The flaw resides in CVE-2025-21042, a critical 9.8/10 out-of-bounds write in libimagecodec.quram.so exploited via malformed.DNG raw image files shared over WhatsApp, affecting Android versions 13 through 15.
  • Unit 42's analysis shows Landfall spyware records audio, calls, location and accesses photos, contacts, SMS, call logs, files, targeting Iraq, Iran, Turkey and Morocco with C2 infrastructure resembling Stealth Falcon operations.
  • Samsung issued a patch in April after reports from Meta and WhatsApp Security Teams, and CISA urged all organizations to prioritize patching or discontinue use if mitigations are unavailable.
  • This episode fits a wider pattern, as Unit 42 said Landfall exploits DNG image-processing vulnerabilities in mobile spyware and Itay Cohen said it suggests government-backed espionage but lacks conclusive vendor links.
Insights by Ground AI

29 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 67% of the sources are Center
67% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

IMP broke the news in on Monday, November 10, 2025.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal