We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary code via a crafted .js file. NOTE: the GitHub README says "Ladybird is in a pre-alpha state, and only suitable for use by developers."
Reserved 2025-05-01 | Published 2025-05-01 | Updated 2025-05-01 | Assigner mitreCWE-820 Missing Synchronization
news.ycombinator.com/item?id=43852096
jessie.cafe/posts/pwning-ladybirds-libjs/
github.com/...ommit/f5a670421954fc7130c3685b713c621b29516669
Support options