CVE-2025-47154
CRITICAL
Published 2025-05-01T00:00:00.000Z
Actions:
CVSS Score
V3.1
9.0
/10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score Metrics
Exploitability: N/A
Impact: N/A
Attack Vector Metrics
Impact Metrics
Description
LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary code via a crafted .js file. NOTE: the GitHub README says "Ladybird is in a pre-alpha state, and only suitable for use by developers."
Available Exploits
No exploits available for this CVE.
Related News
Critical UAF Vulnerability Discovered in Ladybird Browser Engine (CVE-2025-47154)
The Ladybird browser engine, a relatively new entrant originating from the SerenityOS project, has been found to contain The post Critical UAF Vulnerability Discovered in Ladybird Browser Engine (CVE-2025-47154) appeared first on Daily CyberSecurity.
SecurityOnline.info
2025-05-02 00:43
References
Published: 2025-05-01T00:00:00.000Z
Last Modified: 2025-05-01T15:33:42.106Z
Copied to clipboard!