See the Complete Picture.
Published loading...Updated

Google fixes actively exploited FreeType flaw on Android

  • Google released the May 2025 Android security update fixing 46 vulnerabilities, including an actively exploited FreeType flaw affecting Android 13, 14, and 15.
  • This update comes after Facebook’s March 2025 disclosure of CVE-2025-27363, a critical out-of-bounds write vulnerability affecting FreeType releases up to and including version 2.13.0, which has seen limited targeted exploitation.
  • The FreeType vulnerability occurs during the processing of font subglyph data in TrueType GX and variable fonts, enabling local code execution without requiring user involvement or elevated privileges.
  • CVE-2025-27363 has a CVSS score of 8.1 and represents the most urgent risk among 8 Android System and 15 Framework component flaws addressed in the update.
  • Google urges users to promptly install the update as older versions like Android 12 no longer receive fixes, which could expose devices to code execution attacks.
Insights by Ground AI
Does this summary seem wrong?

13 Articles

All
Left
Center
1
Right
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

Global Security Mag Online broke the news in on Tuesday, May 6, 2025.
Sources are mostly out of (0)