Using the wrong font could be a major security problem — and possibly not for the reason you might think

Fonts
(Image credit: Marek Levák / Unsplash)

An investigation by Canva deep dive into the world of font security has uncovered three unexpected vulnerabilities and revealed how choosing the wrong font could spell out a cybersecurity disaster.

In an effort to enhance the security of its tools, Canva has been researching less-explored attack surfaces, including fonts, which play an integral part in graphics processing.

A trio of vulnerabilities have been highlighted in a report entitled “Fonts are still a Helvetica of a Problem", with Canva ultimately declaring that the font landscape is actually quite rich in attack surfaces.

Canva is concerned about the font you use

The first vulnerability, tracked as CVE-2023-45139, was discovered in FontTools, a Python library for manipulating fonts. Canva found that when processing an SVG table to subset a font, FontTools could use an untrusted XML file, leading to an XML External Entity (XXE) vulnerability.

The researchers abused this vulnerability to produce a subsetted font containing an SVG table with an /etc/passwd payload. FontTools released a patch three days after being notified of the vulnerability in September 2023.

The other two vulnerabilities, CVE-2024-25081 and CVE-2024-25082, both rated at 4.2/10, were associated with naming conventions and font compression. Canva found the potential for command injection when dealing with filenames in tools like FontForge and ImageMagick. Both have also been addressed.

Acknowledging the timely work of open-source font software and tool maintainers, Canva noted that IT workers should “treat fonts like any other untrusted input” by implementing sandboxing and using tools like OpenType-Sanitizer.

This isn’t the first time that font security has been raised, with Google exploring similar issues nearly a decade ago, however with the increased prevalence and more severe consequences of cyber attacks, Canva’s recommendation that we pay attention to less obvious attack surfaces is a mighty sensible one.

More from TechRadar Pro

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
SVG files are offering cybercriminals an easy way in with new phishing attacks
email
Hidden text "salting" is letting hackers craft devious email attacks to evade detection
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
WordPress
Another top WordPress plugin found carrying critical security flaws
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)