Vulnerability
Campaign
Malware Activity
Public Sector Action
Security Patch Release
Samsung image library flaw used to deliver LANDFALL spyware
Updated 25.11.2025 08:42
Case score 68
Score breakdown
- Total
- 68
- Lead score
- 63
- Support bonus
- +5 / 20
- Scoring support
- 2
- Context members
- 2
Top contributors
- Vulnerability Defines the Samsung image-processing zero-day exploited before patching and anchors the Case. base
- Malware Activity Supplies direct evidence of malicious DNG delivery, persistence, and surveillance tooling used by LandFall. support
- Campaign Provides the LandFall campaign context, WhatsApp DNG delivery path, and spyware objective tied to CVE-2025-21042. support
- Public Sector Action Shows federal remediation pressure after CISA added CVE-2025-21042 to KEV and set a deadline. context
Case score 68
Members 5
Latest activity 25.11.2025 08:42
Active exploitation
KEV: CISA KEV
Patch available
CVSS: 9.8 Critical
Active exploitation
KEV: CISA KEV
Patch available
CVSS: 9.8 Critical
Members 5
First seen 12.09.2025 12:48
Last seen 11.11.2025 12:30
Updated 25.11.2025 08:42
Overview
**CVE-2025-21042** in Samsung's image processing library was exploited as a zero-day to push **LANDFALL** spyware through malicious **DNG** images sent over **WhatsApp**. The activity affected selected Galaxy devices and was active before Samsung's April patch, with evidence dating back to July 2024.
CISA later added the flaw to the **KEV** catalog and ordered US federal agencies to remediate it by **December 1** or stop using affected products if mitigations are unavailable. Samsung also patched **CVE-2025-21043** in the same library after reporting in-the-wild exploitation, but available evidence still does not quantify total reach or confirm a single public attribution.
Attackers used **CVE-2025-21042** in Samsung's image processing library to deliver **LANDFALL** spyware to Galaxy devices through malicious **DNG** images sent over **WhatsApp**. The exploit path could trigger remote code execution with little or no user interaction, and the activity was already in use before Samsung patched the flaw in April. Available evidence says the campaign has been active since at least July 2024 and focused on selected Galaxy models, including the S22, S23, S24, Z Fold4, and Z Flip4. The payload was built for surveillance rather than simple intrusion, with functions described for microphone recording, location tracking, and collection of device data.
CISA later added **CVE-2025-21042** to the **KEV** catalog and told US federal agencies to apply vendor mitigations by **December 1** or discontinue use if mitigations are unavailable. Samsung also released **SMR Sep-2025 Release 1** for **CVE-2025-21043**, a separate out-of-bounds write in the same image library that Samsung said had been exploited in the wild. Available evidence points to sustained abuse of Samsung's image parsing stack through crafted image content, but it does not yet quantify reach or confirm a single public attribution for both flaws.