By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Samsung warns phone owners about major security issue: “Update your Galaxy phone ASAP”
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Samsung warns phone owners about major security issue: “Update your Galaxy phone ASAP”
News

Samsung warns phone owners about major security issue: “Update your Galaxy phone ASAP”

News Room
Last updated: 2025/09/14 at 11:19 PM
News Room Published 14 September 2025
Share
SHARE

Samsung says that the flaw has been exploited in the wild

The flaw has a severity rating of critical and was reported by messaging app WhatsApp. It is unknown whether the security issue is limited to WhatsApp or affects other messaging platforms. With 3 billion monthly active users, this vulnerability has a large pool of potential victims. The flaw in CVE-2025-21043 is found in a closed-source image parsing library from a company named Quramsoft. The flaw can lead to a vulnerability known as an out-of-bounds write.

A remote attacker can send an image file, created specifically to cause a problem, to a vulnerable device. When the device attempts to process the image, the malicious code is written in a space where it doesn’t belong. This overflow data can contain malicious code, and if it is written into a specific memory location, the attacker can trick the system into executing that code allowing the attacker to take control of the device. This would result in the attacker having access to the victim’s phone.

Because this is a zero-click attack, the victim does not have to do anything to set it off. That makes it more dangerous than your typical phishing scam since there is nothing that you can avoid pressing to prevent the attack from happening. These attacks take place in the background, making it hard for you to know that your phone is compromised. These attacks are considered to be rare because they are so hard to pull off.

Targets of these attacks are usually high-profile individuals

Such attacks are also sophisticated which means they are attempted by well-funded nation-states engaged in some sort of espionage campaign against well-known individuals. Targets include journalists, politicians, diplomats and those working in government defense departments.

A similar zero-click vulnerability targeted to iPhone models was patched by WhatsApp last month. WhatsApp said that it fixed an “incomplete authorization of linked device synchronization messages in WhatsApp.” This “could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device.” Combined with another vulnerability WhatsApp handled last month, the pair of vulnerabilities were exploited against targeted users via a sophisticated attack.

It’s not that hard to protect yourself. Make sure that your Galaxy phone is running the latest version of Android and that all of your apps are also running their latest versions. This might be a little harder with a Galaxy phone than an iPhone or Pixel because Samsung’s updates are rolled out by the model of the phone, the country where the phone is used, and the carrier the phone is connected with. In other words, updates to Galaxy phones are staggered. Nonetheless, as soon as your phone does receive Android and security updates, make sure you install the new files ASAP. 

What if you’re not well known?

Even though these are said to be targeted attacks, it doesn’t mean that you shouldn’t take precautions. Attackers eyes get wide when they are going after a device that doesn’t have the current OS version and a recent security patch installed. Don’t make this easy for them, especially since it is so easy to make sure that your device is running the most up-to-date versions of Android and security updates on your phone.

“Iconic Phones” is coming this Fall!

Good news everyone! Over the past year we’ve been working on an exciting passion project of ours and we’re thrilled to announce it will be ready to release in just a few short months.

“Iconic Phones: Revolution at Your Fingertips” is a must-have coffee table book for every tech-head that will bring you on a journey to relive the greatest technological revolution of the 21st century. For more details, simply follow the link below!

LEARN MORE AND SIGN UP FOR EARLY BIRD DISCOUNTS HERE

Read the latest from Alan Friedman

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Java News Roundup: OpenJDK JEPs, TornadoVM, Spring Framework, Open Liberty, JBang
Next Article Google’s 27th birthday bash comes with Pixel freebies and big discounts
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Link11 Reports 225% more DDoS attacks in H1 2025 with new tactics against infrastructure
Gadget
Microsoft is changing how Xbox controllers work on Windows 11
News
AI chatbot concerns, whistleblower allegations revive kids online safety push
News
Tencent not in talks to acquire Nexon, source says: report · TechNode
Computing

You Might also Like

News

Microsoft is changing how Xbox controllers work on Windows 11

2 Min Read
News

AI chatbot concerns, whistleblower allegations revive kids online safety push

8 Min Read
News

The Pixel 10 made me fall back in love with small phones

9 Min Read
News

Pascal AI raises $3.1M to scale autonomous investment research workflows – News

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?