#cve-2025-21042

[ follow ]
fromTheregister
16 hours ago

Landfall spyware used in 0-day attacks on Samsung phones

A previously unknown Android spyware family called LANDFALL exploited a zero-day in Samsung Galaxy devices for nearly a year, installing surveillance code capable of recording calls, tracking locations, and harvesting photos and logs before Samsung finally patched it in April. The surveillance campaign likely began in July 2024 and abused CVE-2025-21042, a critical bug in Samsung's image-processing library that affects Galaxy devices running Android versions 13, 14, 15, and 16,
Information security
Information security
fromThe Hacker News
19 hours ago

Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp

A zero-day in Samsung's libimagecodec.quram.so (CVE-2025-21042) was exploited to deliver LANDFALL spyware via malicious WhatsApp DNG images targeting the Middle East.
[ Load more ]