Junglewise Threat Intelligence

CVE-2025-27363: FreeType Out-of-Bounds Write Vulnerability

CVE-2025-27363 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2025-05-06

Technologies: FreeType. Vendors: Freetype.

Executive brief

FreeType contains an out-of-bounds write vulnerability when parsing font subglyph structures in TrueType GX and variable font files. An integer wrap-around during heap buffer allocation allows for up to six signed long integers to be written out of bounds, potentially leading to arbitrary code execution.

Affected products

  • FreeType Project FreeType 2.13.0 and below

Timeline

  • 2025-05-06: disclosed
  • 2025-05-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2025-05-06: exploited: Reported as exploited in the wild.

Related threats