HomeSecurityFacebook reveals FreeType 2 flaw that is actively being exploited

Facebook reveals FreeType 2 flaw that is being actively exploited

Facebook is warning that a FreeType in all versions up to version 2.13 could lead to arbitrary code execution, with reports that the flaw has been exploited in attacks.

See also: The impact of social media on mental health

FreeType 2 bug

The FreeType library is a widely used open source font rendering solution that allows text to be displayed and embedded in images programmatically. It offers capabilities for loading and rendering fonts in a variety of formats, including TrueType (TTF), OpenType (OTF), and others.

The library has been integrated into millions of systems and services, including Linux, Android, game engines, GUI frameworks, and web platforms.

The flaw, which was reported as CVE-2025-27363 and rated CVSS v3 severity 8.1 (“high”), was fixed in FreeType version 2.13.0, which was released on February 9, 2023.

Facebook announced the existence of a flaw yesterday, noting that the vulnerability can be exploited in all versions of FreeType up to 2.13, with reports of active attacks exploiting it.

See also: Meta – Global problems on Facebook, Instagram and WhatsApp

Facebook may use FreeType to some extent, but it is unclear whether the attacks security team occurred on its platform or if they discovered them in other sources.

Facebook reveals FreeType 2 flaw that is being actively exploited

Given the extensive implementation of FreeType across various platforms, it is imperative that software developers and project managers upgrade to FreeType version 2.13.3 (the latest) as soon as possible.

Although the latest version of the vulnerable FreeType (2.13.0) was released two years ago, previous versions of the library may remain in software for long periods of time, making it imperative to immediately fix the flaw.

See also: Threads gained 35 million new users in November

The concept of arbitrary code execution refers to the ability of an attacker to execute arbitrary code on a computer system or application without restrictions or checks. This means that the attacker can execute arbitrary code, which can exploit vulnerabilities in the software and cause unwanted actions, such as gaining administrator rights, executing malware , or stealing data. The ability to execute this code is usually the result of a vulnerability in the software, such as a buffer overflow, improper input handling, or other security weaknesses. If there is no adequate input control or process isolation, a malicious user may be allowed to execute arbitrary code in the form of scripts or other commands, which are executed by the system.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS