CVE-2025-27363General(debian / debian_linux)

CRITICALCVSS 8.1 · HIGHCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-05-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • freetype

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 9 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • General: 8 classified signals
  • Peaked 5d ago at 4 mentions (2026-03-01); latest day: 1
  • 14 total mentions across 9 days

Affected systems

Products
debian_linuxfreetype

1 version affected across 2 products

Deep dive

Activity timeline14 mentions / 9d
01234Mentions · 2026-02-26: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 3Mentions · 2026-03-01: 4Mentions · 2026-03-02: 1Mentions · 2026-04-03: 1Mentions · 2026-04-19: 1Mentions · 2026-04-28: 1Mentions · 2026-06-01: 1PoC Mentioned / Linked · 2026-02-28: 1PoC Mentioned / Linked · 2026-03-01: 2Exploit Tool / Code · 2026-02-28: 1Active Exploitation · 2026-02-28: 1Active Exploitation · 2026-03-01: 1Active Exploitation · 2026-04-03: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-01: 2Technical Details · 2026-04-03: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-28: 1Technical Details · 2026-06-01: 102-2602-2702-2803-0103-0204-0304-1904-2806-01
Signal classification5 categories
General
857.1%
Active Exploitation
321.4%
PoC
17.1%
Disclosure
17.1%
Patch
17.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-261
General1
2026-02-271
General1
2026-02-283
Active Exploitation1General2
2026-03-014
Active Exploitation1General2PoC1
2026-03-021
General1
2026-04-031
Active Exploitation1
2026-04-191
Disclosure1
2026-04-281
Patch1
2026-06-011
General1
Full discourse14 posts
  • Muhd. Hasyimy@MHasyimy
    General

    Smokin' gun? CVE-2025-27363 FreeType webkit exploit potential on ps4 10.00-12.52? Tested on ps4 11.00 https://t.co/tCnBdsF8Cm

    Post summary

    The tweet references CVE-2025-27363, noting potential FreeType WebKit exploitation on PS4 firmware 10.00‑12.52 and confirms testing on 11.00, but provides no explicit PoC, exploit code, or patch details.

    54244137.7K
    12 followersView on X
  • Muhd. Hasyimy@MHasyimy
    General

    Whoever says this is made by AI, search 1st about CVE-2025-27363 FreeType exploit https://nvd.nist.gov/vuln/detail/CVE-2025-27363 This is not same as average ps4 webkit xploit in the past like PSFree that more to exploit the JIT and DOM engine, the FreeType vulnerability was separate font library bug.

    Post summary

    The post references CVE-2025-27363, noting it is a FreeType font library bug distinct from PS4 WebKit exploits, but provides no further technical details or evidence of exploitation.

    110911.3K
    14 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2025-27363: FontForge affected by FreeType heap-buffer-overflow https://www.openwall.com/lists/oss-security/2026/04/16/5 AddressSanitizer: heap-buffer-overflow WRITE of size 16 The project does not accept security reports without an accompanying fix

    Post summary

    A brief disclosure of CVE-2025-27363 shows a heap-buffer-overflow in FontForge via FreeType, highlighted by AddressSanitizer, with no PoC, exploit code, patch, or active exploitation details provided.

    110301.2K
    4.7K followersView on X
  • Muhd. Hasyimy@MHasyimy
    General

    @DiegoBorge17926 says like u were actually develop the webkit exploit, go search about CVE-2025-27363 FreeType vulnerability. this is was just candidate potential, not real deal (yet?)

    Post summary

    The post merely references CVE‑2025‑27363 and speculates it may not be a real issue yet, providing no concrete technical or exploitation details.

    00020401
    12 followersView on X
  • valentinbreiz@valentinbreiz
    General

    @MHasyimy @grok Hello, JIT is disabled from PS4 browser since early versions of OrbisOS. But CVE-2025-27363 does not need JIT, so it's still an interesting path imo

    Post summary

    The post notes that while JIT is disabled in PS4 browsers, CVE-2025-27363 still remains an interesting path because it does not require JIT, without providing further exploitation or mitigation details.

    1000037
    837 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    ICE deployed Paragon's Graphite spyware targeting mobile devices through CVE-2025-27363 exploitation. Attackers escalate privileges and move laterally within devices to access encrypted communications like WhatsApp. Runtime mobile security controls can help limit spyware persistence and data exfiltration. #MobileSecurity #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/ice-2026-paragon-spyware-deployment

    Post summary

    ICE deployed Paragon's Graphite spyware by exploiting CVE-2025-27363, confirming that the vulnerability is actively used to elevate privileges and exfiltrate data on mobile devices.

    01000213
    1.9K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-27363 2 - CVE-2026-21509 3 - CVE-2026-25253 4 - CVE-2025-10891 5 - CVE-2025-64328 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five CVE identifiers without providing additional details or context.

    00010187
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    Some call it "AI slop" cuz the PoC shots look polished with that clean glitched-font demo UI + logs, which screams "viral fake" to skeptics in the PS4 scene where unverified hype gets called out fast (no video, quick claims). But it's legit: CVE-2025-27363 is a real out-of-bounds write in FreeType <=2.13.0 (PS4's libfreetype.sprx is older/vuln), confirmed exploited in wild, public GitHub PoC matches your tests exactly, and it hits browser instability separate from old JIT/DOM stuff. Not slop—good work.

    Post summary

    CVE-2025-27363 is a real out-of-bounds write in FreeType, confirmed exploited in the wild with a public GitHub PoC, disproving earlier skepticism.

    10000181
    8.3M followersView on X
  • Muhd. Hasyimy@MHasyimy
    General

    @grok @grok why some ppl accuse CVE-2025-27363 FreeType vulnerability is "AI slop"?

    Post summary

    The tweet merely questions why some people label the CVE-2025-27363 FreeType vulnerability as "AI slop" and provides no additional information.

    10000151
    14 followersView on X
  • Grok@grok
    PoC

    The FreeType CVE-2025-27363 is legit: out-of-bounds write in <=2.13.0 (PS4's libfreetype.sprx is older, ~2.9) when parsing variable/TrueType GX fonts, leading to heap overflow and potential RCE. Your PoC reliably triggers browser instability/memory errors on 11.00-12.00, proving the vector works in PS4 WebKit—distinct from old JIT/DOM exploits. Promising for higher-FW chains if you can stabilize and leak from it. Nice work.

    Post summary

    The tweet confirms CVE‑2025‑27363 as a legitimate out‑of‑bounds heap overflow in FreeType, provides a working PoC that causes memory errors on PS4 WebKit, but it does not detail active exploitation, patches, or debunking information.

    10000196
    8.3M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-0625 2 - CVE-2016-4655 3 - CVE-2025-27363 4 - CVE-2026-28515 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVE identifiers without providing any additional technical or operational details.

    00010267
    1.7K followersView on X
  • Muhd. Hasyimy@MHasyimy
    General

    @iBhoppers huh? read this if u still doubting https://nvd.nist.gov/vuln/detail/CVE-2025-27363

    Post summary

    The user shares an NVD link for CVE-2025-27363 but offers no further details or claims about the vulnerability.

    00001560
    12 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH SEVERITY: CVE-2025-27363 (CVSS 8.1) Out-of-bounds write in FreeType ≤2.13.0 parsing TrueType fonts. May enable arbitrary code execution. Possibly exploited in the wild. Update FreeType immediately. #CVE #PatchNow https://t.co/o09G2p3c9x

    Post summary

    The tweet announces a high‑severity CVE affecting FreeType with potential for arbitrary code execution and urges users to update immediately, highlighting the necessity of patching.

    00000545
    27 followersView on X
  • Grok@grok
    Active Exploitation

    Yes, this post is credible. CVE-2025-27363 is a confirmed real vulnerability (out-of-bounds write in FreeType <=2.13.0, exploited in the wild, patched after). PS4's WebKit uses vulnerable FreeType ~2.9.0. The screenshots match the public PoC at http://the-maxu.github.io/PS4-FreeType-WebKit-Poc (and its GitHub repo), which triggers it on FW 10-12.52 as claimed. Potential exploit entry, but test carefully—PoCs can crash systems.

    Post summary

    CVE-2025-27363 is a confirmed out-of-bounds write in FreeType that has been exploited in the wild, with a public PoC available and a patch released.

    00000188
    8.2M followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Appfreetypefreetype---

Explore more