Google addresses 1 actively exploited vulnerability in May’s Android security update
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-27363 | Out-of-Bounds Write in FreeType Font Parsing Allows Arbitrary Code Execution FreeType, the widely bundled open-source font rendering library, contains an out-of-bounds write (CWE-787) when parsing subglyph structures in TrueType GX and variable font files. The flaw is triggered when an application using FreeType renders a specially crafted font file, such as one embedded in a document, webpage, or downloaded file. A successful exploit may allow the attacker to execute arbitrary code with the privileges of the application that processed the font. Because FreeType ships by default with virtually all major Linux distributions, Android, and many applications and embedded products, the affected population is extremely broad, though specific affected version ranges are not enumerated in the available data. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2025-05-06, indicating confirmed in-the-wild exploitation, and carries a high EPSS probability of 27.8% (98th percentile); no public proof-of-concept code is known. Do: Update FreeType to the latest available release/commit and apply vendor patches for any product that bundles or depends on it, since exact vulnerable version ranges are not stated in the available data. Inventory your environment for software, operating systems, and dependencies that ship FreeType, and prioritize internet-facing or user-facing systems that process untrusted font files. Federal agencies must follow the CISA KEV required action (apply vendor mitigations per BOD 22-01) or discontinue use if mitigations are unavailable. | 8.1 | 28% | KEV |
| masshundreds of millions to billions of devices (FreeType is the default font-rendering library bundled in major Linux distributions and Android) |
Full article536 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The monthly Android security update covers 47 vulnerabilities, including a high-severity defect in the widely used FreeType software library.
Listen to this article
0:00
Learn more.
Google addressed 47 vulnerabilities affecting Android devices in its May security update, including an actively exploited software defect that was first disclosed in March. Google said the high-severity vulnerability, CVE-2025-27363, “may be under limited, targeted exploitation.”
The out-of-bounds write defect in FreeType versions 2.13.0 and below may result in arbitrary code execution, Facebook said in March when it disclosed the vulnerability in a security advisory acting in its capacity as a CVE numbering authority. The vulnerability has a base score of 8.1 on the CVSS scale and is still awaiting further assessment by the National Institute of Standards and Technology’s National Vulnerability Database program.
FreeType is a software library, written in the C programming language, that allows developers to render fonts. The freely available software is used in products contained in more than a billion devices, according to the FreeType Project.
Google’s security update includes 15 high-severity vulnerabilities affecting the Android framework and nine high-severity software defects affecting the Android system. The vulnerabilities, if exploited, could allow attackers to achieve escalation of privileges, remote code execution, local code execution, information disclosure and denial of service.
The Android security update contains two patch levels — 2025-05-01 and 2025-05-05 — allowing Android partners to address a group of 24 common vulnerabilities on different devices.
The second patch includes fixes for two high-severity vulnerabilities affecting Arm components, nine defects in Imagination Technologies components, one flaw in MediaTek components and 11 total vulnerabilities in Qualcomm components.
Google Pixel users automatically get access to the latest Android security updates. Meanwhile, other Android device manufacturers release security patches after they’ve customized operating system updates for their specific hardware.
Google said source code patches for all 47 vulnerabilities covered in this month’s security update will be released to the Android Open Source Project repository by Wednesday.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-may-2025/