Description

LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary code via a crafted .js file. NOTE: the GitHub README says "Ladybird is in a pre-alpha state, and only suitable for use by developers."

INFO

Published Date :

2025-05-01T00:00:00.000Z

Last Modified :

2025-05-01T15:33:42.106Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-47154 vulnerability.

No data.

REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact