Cybersecurity Research

Malicious Image Files Used to Silently Hack Samsung Android Phones via WhatsApp

Project Zero · 13 Dec 2025
Key Takeaway Keep Samsung and Android devices fully updated, as patches for issues like this one close off attack paths that require no user action at all.

Security researchers have uncovered a sophisticated spyware campaign that used malicious image files to compromise Samsung Android devices without any user interaction beyond receiving the image. Between July 2024 and February 2025, six suspicious DNG image files were uploaded to VirusTotal and flagged to Google's Threat Intelligence Group. Analysis showed the images targeted Samsung's Quram image parsing library, a component specific to Samsung devices.

Filenames on several samples indicated the images were delivered via WhatsApp. Once a device downloaded the image, Android automatically stored it in the phone's shared media library. A separate Samsung system service, which periodically scans and processes images and videos for 'smart' features, would then parse the file and inadvertently trigger the exploit. The attack ultimately ran inside this trusted Samsung process, giving it a foothold on the device. Google noted that similar image-based attacks have long been documented on iPhones, but this represents a rare public look at how such attacks work on Android.

Samsung fixed the underlying vulnerability in April 2025, and a related report from Unit 42 has detailed the spyware these exploits delivered. Because the attack required no clicks or downloads beyond simply receiving a message, it highlights how ordinary messaging apps can become a pathway for highly targeted surveillance tools.

Key Takeaway sentence provided separately.

Android Samsung WhatsApp spyware mobile security Project Zero

Summarised by CISO AI from Project Zero. We link back to every original so you can read it yourself.