AISLE discovered a stack buffer overflow in Firefox’s WebAssembly engine that evaded detection for six months despite shipping with its own regression test. The vulnerability, CVE-2025-13016, enabled arbitrary code execution through a single line of incorrect pointer arithmetic, affecting over 180 million Firefox users worldwide.

  • x00z@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    18 hours ago

    They praised WebAssembly so hard but it’s obviously such a dangerous vector.