Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to
VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google chrome Os |
|
CPEs | cpe:2.3:o:google:chrome_os:16093.57.0:*:*:*:*:*:*:* | |
Vendors & Products |
Google
Google chrome Os |
Sun, 13 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 06 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-125 | |
Metrics |
cvssV3_1
|
Tue, 06 May 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description. | |
References |
|

Status: PUBLISHED
Assigner: ChromeOS
Published:
Updated: 2025-05-08T19:15:07.601Z
Reserved: 2025-03-18T20:10:07.777Z
Link: CVE-2025-2509

Updated: 2025-05-06T13:35:05.669Z

Status : Analyzed
Published: 2025-05-06T01:15:50.563
Modified: 2025-10-03T14:47:54.957
Link: CVE-2025-2509

No data.

No data.