Loading HuntDB...

CVE-2025-47154

CRITICAL
Published 2025-05-01T00:00:00.000Z
Actions:

CVSS Score

V3.1
9.0
/10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score Metrics
Exploitability: N/A Impact: N/A

Attack Vector Metrics

Attack Vector
Not Available
Attack Complexity
Not Available
Privileges Required
Not Available
User Interaction
Not Available
Scope
Not Available

Impact Metrics

Confidentiality
Not Available
Integrity
Not Available
Availability
Not Available

Description

LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary code via a crafted .js file. NOTE: the GitHub README says "Ladybird is in a pre-alpha state, and only suitable for use by developers."

Available Exploits

No exploits available for this CVE.

Related News

Critical UAF Vulnerability Discovered in Ladybird Browser Engine (CVE-2025-47154)

The Ladybird browser engine, a relatively new entrant originating from the SerenityOS project, has been found to contain The post Critical UAF Vulnerability Discovered in Ladybird Browser Engine (CVE-2025-47154) appeared first on Daily CyberSecurity.

SecurityOnline.info 2025-05-02 00:43

Affected Products

Affected Versions:

References

Published: 2025-05-01T00:00:00.000Z
Last Modified: 2025-05-01T15:33:42.106Z
Copied to clipboard!