Facebook has disclosed a vulnerability in the FreeType font rendering library, affecting all versions up to 2.13.0. This can lead to arbitrary code execution and is seen exploited in the wild.

FreeType 2 is a widely used open-source library that enables text rendering and manipulation. It is integrated into millions of (embedded) systems and applications, including Linux, Android, game engines, Browsers. GUI frameworks, and online platforms.

Although a non vulnerable version (FreeType 2.13.0 and up) was released on 2023-02-09, it is expected that many vulnerable versions are still in use due to its widespread use of this library.

https://www.bleepingcomputer.com/news/security/facebook-discloses-freetype-2-flaw-exploited-in-attacks/

CVE-2025-27363