Today: 10 April 2026
Samsung Galaxy S26 Leak Explosion: Massive Camera Upgrades, Thinner Designs & a Shocking S Pen Twist
8 November 2025
3 mins read

‘Landfall’ spyware abused Samsung zero‑day (CVE‑2025‑21042) to hack Galaxy phones for months — patched in April: What happened and how to stay safe

Published: November 7, 2025

Security researchers have uncovered a previously unknown, commercial‑grade Android spyware operation—dubbed Landfall—that exploited a zero‑day flaw in Samsung Galaxy phones and ran largely undetected for close to a year, with targets concentrated in parts of the Middle East. Samsung fixed the underlying vulnerability in an April 2025 firmware update, but the campaign and its methods are only now coming to light. TechCrunch+1


What is “Landfall” and how did the hack work?

According to Palo Alto Networks’ Unit 42—whose research underpins today’s coverage—Landfall delivered spyware via malicious image files that abused CVE‑2025‑21042, an out‑of‑bounds write bug in Samsung’s libimagecodec.quram.so library. The booby‑trapped images (Digital Negative, or DNG format) could be sent over messaging apps; Unit 42 says the exploit chain may have been zero‑click (no tap required), though there’s no evidence of an undisclosed WhatsApp bug in this Android campaign. Once processed by the phone, the payload unpacked additional components and modified SELinux policies to expand its data‑stealing reach. Unit 42+1

Landfall’s capabilities include microphone recording, location tracking, and exfiltration of photos, messages, contacts, and call logs—the hallmarks of advanced mobile surveillanceware sold to government customers by private‑sector offensive actors. Unit 42+1


Who was targeted—and for how long?

Unit 42’s timeline points to first samples appearing in July 2024, with additional uploads through February 2025, suggesting a months‑long operation prior to Samsung’s patch. VirusTotal submissions and national CERT reporting indicate potential targeting in Iraq, Iran, Turkey, and Morocco. Researchers describe the operation as a precision espionage effort, not mass malware distribution. Unit 42+2TechCrunch+2


Which devices and Android versions were affected?

Landfall’s code referenced a range of Galaxy flagships—including S22, S23, S24 and Z Fold 4 / Z Flip 4—and targeted devices running Android 13–15 for CVE‑2025‑21042 (patched in SMR Apr‑2025 Release 1). A related image‑processing flaw, CVE‑2025‑21043, affecting Android 13–16, was separately patched in September 2025 after in‑the‑wild exploitation by spyware operators; Unit 42 notes technical parallels but no direct evidence that 21043 was used in the Landfall samples they analyzed. The Hacker News+2Samsung Mobile Security+2


How serious is CVE‑2025‑21042?

NVD lists CVE‑2025‑21042 with a CVSS v3.1 score of 8.8 and vectors consistent with remote code execution when a crafted image is processed. That aligns with Unit 42’s finding that malformed DNG files could trigger the bug and launch the spyware loader. Samsung’s bulletin ties the fix to April 2025 firmware and maps the issue to SVE‑2024‑1969. NVD+1


Any links to known spyware vendors?

Attribution remains unclear. Researchers observed infrastructure and tradecraft overlaps with Stealth Falcon (also known as FruityArmor)—a surveillance outfit previously linked by researchers to operations targeting journalists and dissidents—but stress the similarities are not enough for firm attribution. This fits a broader pattern of private‑sector offensive actors (PSOAs) running bespoke, government‑focused hacking tools. TechCrunch+1


Why are DNG image bugs suddenly a big deal?

Landfall is part of a 2024–2025 wave of attacks abusing image‑parsing flaws across mobile platforms. In August 2025, Apple patched CVE‑2025‑43300, and Meta/WhatsApp disclosed CVE‑2025‑55177 as part of a chained iOS exploit targeting fewer than 200 users. In September 2025, Samsung fixed CVE‑2025‑21043 in the same image library affected by Landfall’s 21042 exploit. The common thread: carefully crafted image files processed by system libraries can yield zero‑click compromise. Unit 42+1


What Samsung users should do now

  • Update immediately. Ensure your Galaxy device shows the latest Security Maintenance Release (SMR)—April 2025 or later for CVE‑2025‑21042, and September 2025 or later for CVE‑2025‑21043. On most devices: Settings → Software update → Download and install. Samsung Mobile Security
  • Verify your patch level. Confirm your device’s Android security update level and firmware build are current; Samsung’s advisories list the CVEs and SMR months that include fixes. Samsung Mobile Security
  • Harden messaging settings. While no new WhatsApp flaw is implicated on Android here, consider limiting auto‑download of media from unknown senders and keep apps updated from official stores. The Hacker News
  • Enterprise defenders: Review Unit 42’s technical write‑up for IOCs (hashes, network indicators) and detection guidance, and hunt for suspicious image‑processing crashes or anomalous libimagecodec activity around the 2024–early‑2025 window. Unit 42

Key dates and facts at a glance

  • Sept. 25, 2024: Vulnerability privately reported to Samsung (later assigned CVE‑2025‑21042 / SVE‑2024‑1969). Unit 42+1
  • July 2024 – Feb. 2025: Landfall samples uploaded to VirusTotal; targeting observed across parts of the Middle East/North Africa. Unit 42
  • April 2025: Samsung patches CVE‑2025‑21042 in the SMR Apr‑2025 update. Samsung Mobile Security
  • Aug.–Sept. 2025: Parallel iOS/WhatsApp exploit chain disclosed; Samsung patches CVE‑2025‑21043 (same library). Unit 42
  • Nov. 7, 2025: Unit 42 publishes research; outlets confirm the campaign’s scope and targets. Unit 42+2TechCrunch+2

The bottom line

Landfall underscores how quietly weaponized media files can turn a phone into a live microphone and tracking device—without a tap. If you use a Samsung Galaxy device, the fix has been out for months, but protection only comes once you install it. For organizations with high‑risk users, treat image‑parsing RCE on mobile as a priority threat category and ensure rapid SMR adoption, mobile EDR coverage, and targeted threat hunting that includes DNG‑based exploit chains. The Hacker News+1


Sources, November 7, 2025 coverage and primary research: Unit 42 technical report; TechCrunch; The Hacker News; SecurityWeek; The Record; The Register; Samsung advisories / NVD. NVD+7Unit 42+7TechCrunch+7

Stock Market Today

  • AstraZeneca Share Price Up 55% in One Year: Is the Stock Still Undervalued?
    April 10, 2026, 3:21 AM EDT. AstraZeneca (LSE:AZN) has surged 55.1% over the past year, closing recently at £152.76. Despite strong gains, a Discounted Cash Flow (DCF) analysis indicates the stock trades at a 36.2% discount to its intrinsic value of US$239.40 per share, suggesting it remains undervalued. The DCF model projects free cash flow growing from US$9.5 billion currently to US$20.2 billion by 2030. However, the price-to-earnings (P/E) ratio of 31.1x exceeds both the Pharmaceuticals industry average of 21.9x and peer average of 12.4x, signaling a premium valuation relative to earnings. Investors should weigh growth prospects and valuation models carefully amid recent price momentum and sector dynamics.

Latest article

Wall Street Feels the Heat (and Thrill): Fed Cuts, Tariffs & Mega-Mergers Set NYSE Buzz

US Stock Market Today: Live Updates 10.04.2026

10 April 2026
LIVEMarkets rolling coverageStarted: April 10, 2026, 12:00 AM EDTUpdated: April 10, 2026, 3:21 AM EDT AstraZeneca Share Price Up 55% in One Year: Is the Stock Still Undervalued? April 10, 2026, 3:21 AM EDT. AstraZeneca (LSE:AZN) has surged 55.1% over the past year, closing recently at £152.76. Despite strong gains, a Discounted Cash Flow (DCF) analysis indicates the stock trades at a 36.2% discount to its intrinsic value of US$239.40 per share, suggesting it remains undervalued. The DCF model projects free cash flow growing from US$9.5 billion currently to US$20.2 billion by 2030. However, the price-to-earnings (P/E) ratio of 31.1x
MARA Holdings Stock Rises Even After Target Cut as Bitcoin Miner Leans Harder Into AI

MARA Holdings Stock Rises Even After Target Cut as Bitcoin Miner Leans Harder Into AI

9 April 2026
MARA Holdings shares rose 1.7% to $9.67 Thursday despite Cantor Fitzgerald cutting its price target to $10. The company recently sold 15,133 bitcoin for $1.1 billion and agreed to repurchase $1 billion in convertible notes at a discount. MARA is expanding into AI and cloud infrastructure, but fourth-quarter revenue fell 6% and it posted a $1.7 billion net loss.
CoreWeave secures fresh $21 billion Meta AI deal as debt push raises stakes

CoreWeave secures fresh $21 billion Meta AI deal as debt push raises stakes

9 April 2026
Meta Platforms signed a new $21 billion deal with CoreWeave for AI cloud computing capacity through 2032, according to a securities filing. CoreWeave shares rose 3.4% in after-hours trading. The agreement adds to a $14.2 billion commitment disclosed last September. CoreWeave also launched $3 billion in convertible notes and upsized a senior-notes deal to $1.75 billion.
Tesla Revives Cheaper EV Push With New Compact SUV as Sales Pressure Builds

Tesla Revives Cheaper EV Push With New Compact SUV as Sales Pressure Builds

9 April 2026
Tesla is developing a lower-cost compact SUV, with initial production planned for Shanghai, Reuters reported Thursday. The company built 408,386 vehicles and delivered 358,023 in the first quarter, leaving its widest gap in at least four years. Reuters said the new SUV likely will not reach production this year. Tesla did not respond to questions about the project.
NIO ES9 Price Starts at 528,000 Yuan as Flagship SUV Bet Faces China EV Slump

NIO ES9 Price Starts at 528,000 Yuan as Flagship SUV Bet Faces China EV Slump

9 April 2026
NIO opened pre-orders for its ES9 flagship SUV Thursday, pricing it at 528,000 yuan with battery or 420,000 yuan under its Battery-as-a-Service plan. March deliveries rose 136% year-on-year, but NIO’s U.S. shares fell 4.9% after the announcement. The ES9 enters a shrinking premium SUV market in China, competing with Li Auto and Aito. CEO William Li warned chip shortages could add up to 10,000 yuan per vehicle.
Android Auto gets Gemini today (Nov 7, 2025): Live support begins rolling out, what’s new in v15.4, and what’s coming next
Previous Story

Android Auto gets Gemini today (Nov 7, 2025): Live support begins rolling out, what’s new in v15.4, and what’s coming next

Sharper Black Hole Images Could Put Einstein’s Gravity to the Test: New Study Maps What Future Telescopes Must See (7 Nov 2025)
Next Story

Brighter Than 10 Trillion Suns: Record Black Hole Flare 10 Billion Light‑Years Away

Go toTop