{"id":157760,"date":"2025-09-15T05:55:11","date_gmt":"2025-09-15T05:55:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/157760\/"},"modified":"2025-09-15T05:55:11","modified_gmt":"2025-09-15T05:55:11","slug":"samsung-issues-emergency-update-for-most-galaxy-users","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/157760\/","title":{"rendered":"Samsung Issues Emergency Update For Most Galaxy Users"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/09\/1757915711_236_960x0.jpg\" alt=\"Samsung Galaxy S25 And Galaxy S25 Ultra Mobile Phones\" data-height=\"1950\" data-width=\"2926\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Update now \u2014 attacks underway<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Republished on September 14 with Google\u2019s surprising change to security updates; this will have a huge impact on Samsung users almost immediately. <\/p>\n<p>Samsung has <a class=\"color-link\" href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/security.samsungmobile.com\/securityUpdate.smsb\" aria-label=\"suddenly warned\">suddenly warned<\/a> that attacks on Galaxy smartphones are underway. The company has revised its September security update and all eligible phones will now receive the fix. The threat affects devices running Android 13 or newer.<\/p>\n<p>CVE-2025-21043 was reported by WhatsApp in the same way as <a class=\"color-link\" href=\"https:\/\/www.whatsapp.com\/security\/advisories\/2025?lang=en_US\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.whatsapp.com\/security\/advisories\/2025?lang=en_US\" aria-label=\"CVE-2025-55177\">CVE-2025-55177<\/a>, which affected Apple\u2019s iPhone and was flagged last month. Samsung says it \u201cwas notified that an exploit for this issue has existed in the wild.\u201d<\/p>\n<p>The memory vulnerability within an image-parsing library opens the door for attackers to run malicious code on remote devices. It\u2019s not clear yet if this impacts other messengers or just WhatsApp. But with 3 billion users, WhatsApp is installed on almost all Galaxy phones and so provides a vast attack surface.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/09\/14\/microsoft-windows-deadline-30-days-to-update-or-stop-using-your-pc\/\" target=\"_blank\" aria-label=\"Microsoft Windows Deadline\u201430 Days To Update Or Stop Using Your PC\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/09\/14\/microsoft-windows-deadline-30-days-to-update-or-stop-using-your-pc\/\" rel=\"nofollow noopener\">ForbesMicrosoft Windows Deadline\u201430 Days To Update Or Stop Using Your PCBy Zak Doffman<\/a><\/p>\n<p>Zimperium\u2019s Brian Thornton told me this zero-day &#8220;shows just how fast attackers are shifting to mobile as their way in. In this case, a closed-source image library created a broad risk across Samsung devices and the apps that depend on it.\u201d<\/p>\n<p>Samsung says the risk is an \u201cout-of-bounds write in libimagecodec.quram,\u201d third-party image handling software that has triggered past security interest from Google\u2019s <a class=\"color-link\" href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/07\/mms-exploit-part-1-introduction-to-qmage.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/googleprojectzero.blogspot.com\/2020\/07\/mms-exploit-part-1-introduction-to-qmage.html\" aria-label=\"Project Zero\">Project Zero<\/a>. The threat was disclosed on August 13 and affects Android 13, 14, 15 and 16.<\/p>\n<p>\u201cBoth Samsung and WhatsApp have released patches to address this issue,\u201d Black Duck\u2019s Nivedita Murthy confirms. \u201cThis recently identified vulnerability can be exploited to gain unauthorized access to a user\u2019s device and its stored data.\u201d<\/p>\n<p>Unsurprisingly the vulnerability has been given a critical severity rating. Unfortunately, Samsung\u2019s challenge is that while applying the fix is urgent, users must await their turn. Unlike Pixel\u2019s or iPhone\u2019s everyone, everywhere update, it\u2019s not as simple with the Galaxy rollout by model, region and carrier.<\/p>\n<p>Given the similar zero-days, this contrasts unfavorably with Apple\u2019s ability to patch all iPhones right away, in much the same way as iOS 26 will be deployed onto iPhones globally next week while most Galaxy owners face a long wait for One UI 8.<\/p>\n<p>As long as your device is on Samsung\u2019s <a class=\"color-link\" href=\"https:\/\/security.samsungmobile.com\/workScope.smsb\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/security.samsungmobile.com\/workScope.smsb\" aria-label=\"monthly update\">monthly update<\/a> schedule, you will be in line for the fix. Just ensure you install the update and reboot your phone as soon as you can.<\/p>\n<p>Meanwhile, Google has just revealed (via <a class=\"color-link\" href=\"https:\/\/www.androidauthority.com\/android-risk-based-security-updates-3597466\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.androidauthority.com\/android-risk-based-security-updates-3597466\/\" aria-label=\"Android Authority\">Android Authority<\/a>) a completely new approach to monthly security updates that will have a major impact on Samsung and how the company updates its Galaxy devices in the future.<\/p>\n<p>Instead of a monthly update that collates all fixes ready at that time and rolls them out, Google\u2019s revised monthly cadence will be reserved for critical fixes only \u2014 such as the zero-days it confirmed in the monthly update for this month.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/09\/13\/if-you-see-this-message-your-iphone-is-under-attack\/\" target=\"_blank\" aria-label=\"If You See This Message, Your iPhone Is Under Attack\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/09\/13\/if-you-see-this-message-your-iphone-is-under-attack\/\" rel=\"nofollow noopener\">ForbesIf You See This Message, Your iPhone Is Under AttackBy Zak Doffman<\/a><\/p>\n<p>The basket of lesser fixes will roll out quarterly, meaning you\u2019ll have two critical only monthly updates with a handful of fixes at most, and then a bumper third month.<\/p>\n<p>Samsung wraps Google\u2019s Android updates with its own each month, so we\u2019ll have to wait to see if it adapts its own approach to match Google. Otherwise we\u2019ll find limited Android updates and more Samsung updates two months out of every three.<\/p>\n<p>\u201cIf you already receive monthly security updates,\u201d Android Authority says, \u201cyou\u2019ll continue to get them. If you don\u2019t, this change may help your device\u2019s manufacturer deliver them more consistently. At the very least, it should make it easier for all OEMs to push out the quarterly updates.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Update now \u2014 attacks underway NurPhoto via Getty Images Republished on September 14 with Google\u2019s surprising change to&hellip;\n","protected":false},"author":2,"featured_media":157761,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[96205,23213,23212,96204,96203,86140,96206,96202,74],"class_list":{"0":"post-157760","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-samsunbg-s24-update","9":"tag-samsung-android-16","10":"tag-samsung-one-ui-8","11":"tag-samsung-s25-update","12":"tag-samsung-s26-update","13":"tag-samsung-update","14":"tag-samsung-vs-pixel","15":"tag-samsung-whatsapp-zero-day","16":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/157760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=157760"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/157760\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/157761"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=157760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=157760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=157760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}