In our modern digital landscape, software issues sometimes pop up that require urgent fixes. One such fix is currently rolling out for Samsung Galaxy phones as we speak, and if you haven’t checked your phone for updates today, you may want to. The bug it fixes is a doozy.
The issue has a very technical name called CVE-2025-21043. Per Samsung’s update page , the bug allowed attackers to conduct an “out-of-bounds write in libimagecodec.quram.so ” that “allows remote attackers to execute arbitrary code.”
According to Google Project Zero , libimagecodec.quram.so is a closed-source tool that third-party messaging apps use to parse images that attackers could use to hijack a person’s smartphone. The patch going out to Samsung devices now fixes an “incorrect implementation” of the t