Zero-Click, Zero-Warning: The FreeType Flaw Behind a Spyware Surge episode artwork

EPISODE · Jun 23, 2025 · 57 MIN

Zero-Click, Zero-Warning: The FreeType Flaw Behind a Spyware Surge

from Daily Security Review · host Daily Security Review

In this episode, we dive deep into the story behind CVE-2025-27363, a critical zero-click vulnerability in the widely used FreeType font rendering library. Initially discovered by Facebook’s security team and patched by Google in May 2025, this flaw allowed attackers to execute arbitrary code on Android devices—without any user interaction—by exploiting how FreeType parsed certain font structures.This seemingly obscure bug became a key attack vector for Paragon Solutions’ "Graphite" spyware, an Israeli-made surveillance tool capable of taking near-total control of compromised smartphones. Through forensic analysis, it was revealed that Paragon’s spyware leveraged CVE-2025-27363 to infect targets via WhatsApp: malicious PDF files sent through groups triggered the vulnerability, which then deployed Graphite and escaped Android’s sandbox protections. The spyware could then exfiltrate encrypted chats, enable microphones and cameras, and track real-time GPS—without the user’s knowledge.Our discussion also explores:The technical nuances of the vulnerability—how a signed/unsigned integer mismatch led to a dangerous heap overflow.The patching timeline, and Google’s move toward replacing FreeType with the safer Rust-based Skrifa library.How governments in countries like Australia, Canada, Italy, and Israel are suspected of deploying this spyware.The role of The Citizen Lab in uncovering evidence of targeted attacks against journalists, activists, and civil society members—despite Paragon’s public claims of safeguarding human rights.Practical advice for detecting spyware infections and why hybrid detection strategies offer the best protection.Finally, we examine the broader implications for software supply chains, surveillance ethics, and why even basic libraries like font parsers must be designed with security in mind. Tune in for an eye-opening look at how a small coding bug cascaded into a global espionage tool.

Episode metadata supplied by the publisher feed · Published Jun 23, 2025

Embed this episode

NOW PLAYING

Zero-Click, Zero-Warning: The FreeType Flaw Behind a Spyware Surge

0:00 57:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Daily Security Review?

This episode is 57 minutes long.

When was this Daily Security Review episode published?

This episode was published on June 23, 2025.

Can I download this Daily Security Review episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!