CVE-2025-27363
Last modified
CVE-2025-27363 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. CISA has confirmed active exploitation in the wild. EPSS estimates a 23.36% chance of exploitation in the next 30 days.
Description
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freetype | Freetype | <= 2.13.0 |
| Debian | Debian Linux | 11.0 |
References
- https://www.facebook.com/security/advisories/cve-2025-27363Third Party Advisory
- https://source.android.com/docs/security/bulletin/2025-05-01Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27363US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-27363?
How severe is CVE-2025-27363?
How do I fix CVE-2025-27363?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27358Improper Neutralization of Script-Related HTML Tags in a Web…4.6
- CVE-2025-27359Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP…4.3
- CVE-2025-2736A vulnerability was found in PHPGurukul Old Age Home Managem…9.8
- CVE-2025-27360Cross-Site Request Forgery (CSRF) vulnerability in WP Corner…4.3
- CVE-2025-27361Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-27362Improper Control of Filename for Include/Require Statement i…8.1
- CVE-2025-27364In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a R…10
- CVE-2025-27365IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0…6.5
- CVE-2025-27367IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to…6.5
- CVE-2025-27368IBM OpenPages 9.0 and 9.1 is vulnerable to information discl…4.3
- CVE-2025-27369IBM OpenPages with Watson 8.3 and 9.0 is vulnerable …4.3
- CVE-2025-2737A vulnerability was found in PHPGurukul Old Age Home Managem…9.8
Are you affected by CVE-2025-27363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
