Skip to content

[BUG] Bump libexpat in Skia deps to ≥2.7.2 (CVE-2025-59375) #3389

@pkedalag

Description

@pkedalag

Description

https://nvd.nist.gov/vuln/detail/CVE-2025-59375 affects libexpat < 2.7.2 . Request to update third_party/libexpat to R_2_7_2 (libexpat 2.7.2+) and rebuild Skia so downstream native assets like SkiaSharp do not contain the vulnerable expat.

Code

.

Expected Behavior

No response

Actual Behavior

No response

Version of SkiaSharp

3.116.0 (Current)

Last Known Good Version of SkiaSharp

2.88.9 (Previous)

IDE / Editor

Visual Studio Code (Windows)

Platform / Operating System

Windows

Platform / Operating System Version

No response

Devices

No response

Relevant Screenshots

No response

Relevant Log Output

Code of Conduct

  • I agree to follow this project's Code of Conduct

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Status

    New

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions