VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13390 | Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description. |
Fri, 03 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google chrome Os |
|
| CPEs | cpe:2.3:o:google:chrome_os:16093.57.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Google
Google chrome Os |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 06 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-125 | |
| Metrics |
cvssV3_1
|
Tue, 06 May 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description. | |
| References |
|
Status: PUBLISHED
Assigner: ChromeOS
Published:
Updated: 2026-02-26T18:29:03.368Z
Reserved: 2025-03-18T20:10:07.777Z
Link: CVE-2025-2509
Updated: 2025-05-06T13:35:05.669Z
Status : Analyzed
Published: 2025-05-06T01:15:50.563
Modified: 2025-10-03T14:47:54.957
Link: CVE-2025-2509
No data.
OpenCVE Enrichment
No data.
EUVD