A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2025-27363

FreeType Out-of-Bounds Write Vulnerability

Published
2025-05-06
Modified
2026-07-31
Sources
cisa-kev

Summary

FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.