AISLE discovered a stack buffer overflow in Firefox’s WebAssembly engine that evaded detection for six months despite shipping with its own regression test. The vulnerability, CVE-2025-13016, enabled arbitrary code execution through a single line of incorrect pointer arithmetic, affecting over 180 million Firefox users worldwide.

  • who@feddit.org
    link
    fedilink
    English
    arrow-up
    9
    ·
    12 hours ago

    affected all Firefox versions from 143 through early 145, and Firefox ESR versions before 140.5

  • x00z@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    12 hours ago

    They praised WebAssembly so hard but it’s obviously such a dangerous vector.