← Back to CVE intelligence
CVE intelligenceCISA KEV

CVE-2025-27363

FreeType Out-of-Bounds Write Vulnerability

Published Mar 11, 2025Sources checked Sep 30, 2026
8.1HIGHCVSS out of 10
What this means

Actively exploited

CISA lists CVE-2025-27363 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to FreeType FreeType.

  • Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
What to do next

Remediation and response

CISA KEVListedObserved exploitation
EPSS27.8%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2025-27363?

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.