The digital landscape has just gotten a whole lot more dangerous for millions of Samsung mobile users. A severe vulnerability, officially tracked as CVE-2025-21042, has not only been discovered—it's been actively exploited in the wild for months.
On November 10, 2025, the US Cybersecurity and Infrastructure Security Agency (CISA) delivered a thunderclap to the industry, adding this flaw to its infamous Known Exploited Vulnerabilities (KEV) catalog. When CISA flags a vulnerability, it is the ultimate signal of urgency: confirmation of active, real-world exploitation, and a mandatory deadline for federal agencies to patch.
The Silent Assassin: Zero-Click RCE
This is not a simple bug you can ignore. CVE-2025-21042 is an out-of-bounds write vulnerability nested deep within Samsung’s image processing library. This type of flaw is a hacker's dream because it allows attackers to execute arbitrary code and potentially seize complete control of a device—without the victim doing a single thing.
This is the dreaded "zero-click" attack: no taps, no opens, no interaction required. Simply processing a booby-trapped file is enough to compromise your phone. The attacker gains the keys to your device silently, completely bypassing any warning signs.
LANDFALL: The Spyware Delivered via WhatsApp
The stakes are impossibly high: data theft, complete surveillance, and compromised mobile devices being used as secret footholds for broader corporate attacks.
Research from Unit 42 indicates that this zero-day flaw was weaponized to deploy the sophisticated LANDFALL spyware, particularly targeting Galaxy devices in the Middle East. Now, other criminals will be quickly moving to adopt the playbook.
The Attack Chain is as Clever as it is Silent:
-
A victim receives a seemingly innocuous Digital Negative (DNG) image file—an open RAW format popular with photographers—via an app like WhatsApp.
-
This DNG file is booby-trapped with tailored exploit code.
-
The moment the device processes the image (even just preparing a thumbnail preview), the vulnerability is triggered in the Samsung image codec library.
-
The attacker executes code, leading to full device takeover and the installation of surveillance software.
Time is Running Out: Patch Now
Samsung released a patch for this critical issue back in April 2025. However, CISA’s recent action confirms that attackers have been ahead of the curve, successfully leveraging the flaw for months. Image processing flaws, like this one and a similar one patched in September 2025 (CVE-2025-21043), are becoming the entry point of choice for the most dangerous cyber campaigns.
The following high-risk models are known to be targeted by the LANDFALL spyware:
-
Galaxy S24 Series
-
Galaxy S23 Series
-
Galaxy S22
-
Galaxy Z Fold4
-
Galaxy Z Flip4
This crucial security notice was brought to you by StormWarning!
Is your team secure? Find out more about how StormWarning! can assist to harden your organisation against CyberCrime!