logo

Facebook discloses FreeType 2 flaw exploited in attacks

ID: dfa62c87-20e3-59f6-a354-94a7abda7464

STIX ID: report--dfa62c87-20e3-59f6-a354-94a7abda7464

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-03-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Facebook warns of a high-severity FreeType vulnerability (CVE-2025-27363, CVSS v3 8.1) present in versions up to 2.13 that permits arbitrary code execution via an out-of-bounds write when parsing TrueType GX/variable font subglyphs; exploitation has been reported and administrators should upgrade to FreeType 2.13.3 (latest) immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.