Executive brief
A heap buffer overflow vulnerability exists in the FreeType font rendering library, specifically within the Load_SBit_Png function when processing PNG images embedded in fonts. A remote attacker can exploit this via a crafted HTML page to cause heap corruption, potentially leading to arbitrary code execution.
Affected products
- Google Chrome prior to 86.0.4240.111
- FreeType FreeType
Timeline
- 2020-10-20: patched: Stable channel update for desktop 86.0.4240.111 released.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: NVD publication date.