Vulnerability Description
Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome Os | 16093.57.0 |
Related Weaknesses (CWE)
References
- https://issues.chromium.org/issues/b/385851796Broken Link
- https://issuetracker.google.com/issues/385851796ExploitIssue Tracking
FAQ
What is CVE-2025-2509?
CVE-2025-2509 is a vulnerability with a CVSS score of 7.8 (HIGH). Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via c...
How severe is CVE-2025-2509?
CVE-2025-2509 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-2509?
Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome Os.