Google fixes actively exploited FreeType flaw on Android
- Google released the May 2025 Android security update fixing 46 vulnerabilities, including an actively exploited FreeType flaw affecting Android 13, 14, and 15.
- This update comes after Facebook’s March 2025 disclosure of CVE-2025-27363, a critical out-of-bounds write vulnerability affecting FreeType releases up to and including version 2.13.0, which has seen limited targeted exploitation.
- The FreeType vulnerability occurs during the processing of font subglyph data in TrueType GX and variable fonts, enabling local code execution without requiring user involvement or elevated privileges.
- CVE-2025-27363 has a CVSS score of 8.1 and represents the most urgent risk among 8 Android System and 15 Framework component flaws addressed in the update.
- Google urges users to promptly install the update as older versions like Android 12 no longer receive fixes, which could expose devices to code execution attacks.
13 Articles
13 Articles
May 2025 Android Security Bulletin Fixes 46 Vulnerabilities
Google has published its Android Security Bulletin for May 2025, delivering critical updates to the Android ecosystem. This monthly update resolves 46 vulnerabilities, one of which—CVE-2025-27363—has already been exploited in the wild. CVE-2025-27363, a high-severity vulnerability with a CVSS score of 8.1, lies at the core of Google's May 2025 Android Security Bulletin. Located in the Android System component, this flaw enables local code execu…
Google Patches Android's Critical Flaw Already Under Attack
Here’s a little heads-up for all you mobile aficionados out there. Google has just shared its May 2025 security bulletin for this month’s update, and it’s packed with fixes for a whopping 46 security vulnerabilities found on Android. That’s a lot of digital patching to keep our devices safe and sound. However, there’s a dark side since one of the vulnerabilities has been exploited. There’s one particular fix in this update that’s got our attenti…
Android fixes 47 vulnerabilities, including one zero-day. Update as soon as you can!
Google has patched 47 vulnerabilities in Android, including one actively exploited zero-day vulnerability in its May 2025 Android Security Bulletin. Introduction to Malware Binary Triage (IMBT) Course Looking to level …
Coverage Details
Bias Distribution
- 100% of the sources are Center
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage