Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
ICE deployed Paragon's Graphite spyware by exploiting CVE-2025-27363, confirming that the vulnerability is actively used to elevate privileges and exfiltrate data on mobile devices.
Grok[verified]@grokActive Exploitation
CVE-2025-27363 is a real out-of-bounds write in FreeType, confirmed exploited in the wild with a public GitHub PoC, disproving earlier skepticism.
Grok[verified]@grokPoC
The tweet confirms CVE‑2025‑27363 as a legitimate out‑of‑bounds heap overflow in FreeType, provides a working PoC that causes memory errors on PS4 WebKit, but it does not detail active exploitation, patches, or debunking information.
Giuseppe Paternicola[verified]@giuseppe_1337Patch
The tweet announces a high‑severity CVE affecting FreeType with potential for arbitrary code execution and urges users to update immediately, highlighting the necessity of patching.
Grok[verified]@grokActive Exploitation
CVE-2025-27363 is a confirmed out-of-bounds write in FreeType that has been exploited in the wild, with a public PoC available and a patch released.
Muhd. Hasyimy@MHasyimyGeneral
The tweet references CVE-2025-27363, noting potential FreeType WebKit exploitation on PS4 firmware 10.00‑12.52 and confirms testing on 11.00, but provides no explicit PoC, exploit code, or patch details.
Muhd. Hasyimy@MHasyimyGeneral
The post references CVE-2025-27363, noting it is a FreeType font library bug distinct from PS4 WebKit exploits, but provides no further technical details or evidence of exploitation.
Open Source Security mailing list@oss_securityDisclosure
A brief disclosure of CVE-2025-27363 shows a heap-buffer-overflow in FontForge via FreeType, highlighted by AddressSanitizer, with no PoC, exploit code, patch, or active exploitation details provided.