Tag: LANDFALL

Samsung Mobile Flaw Exploited as Zero-Day to Deploy LANDFALL Android Spyware
News

Samsung Mobile Flaw Exploited as Zero-Day to Deploy LANDFALL Android Spyware

In targeted assaults within the Middle East, a security vulnerability in Samsung Galaxy Android devices that has now been fixed was exploited as a zero-day to deploy LANDFALL, an "commercial-grade" Android spyware. Palo Alto Networks Unit 42 reported that the activity involved taking advantage of CVE-2025-21042 (CVSS score: 8.8), which is an out-of-bounds write vulnerability in the "libimagecodec.quram.so" component that could permit remote attackers to run arbitrary code. In April 2025, Samsung dealt with the issue. According to Unit 42, this vulnerability was actively exploited in the wild before Samsung implemented a patch for it in April 2025, after reports of real-world attacks. Based on VirusTotal submission data, potential targets of the activity tracked read more about Samsu...