CVE Database
/

CVE-2025-2509

Back to search

CVE-2025-2509

Published: May 6, 2025

Modified: Feb 26, 2026

PUBLISHED

Description

Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.

VendorProductVersions

Google

ChromeOS

affected
16093.57.0 - < 16093.57.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now