A vulnerability in LibJS allows code execution when opening a page in the Ladybird browser.

A vulnerability (CVE-2025-47154) has been identified in the JavaScript engine LibJS, used in the Ladybird web browser, allowing the execution of arbitrary code on the system when processing specially crafted JavaScript code. The vulnerability is caused by the deallocation of memory on the m_argument_values_buffer vector, where a pointer remained in the arguments_list structure, leading to access to already freed memory. A working prototype of the exploit is available.

The researcher who discovered the issue conducted fuzzing tests on LibJS, during which 10 crashes were documented. An analysis of one of the crashes revealed that the vulnerability could be exploited when processing JavaScript code. The vulnerability allowed reading and writing to arbitrary memory areas of the process. Code execution was organized in the exploit by replacing the return pointer from the rendering function. A chain was formed for executing the execve system call to launch an external application using return-oriented programming (ROP).

The Ladybird browser is being developed by Andreas Kling, who previously worked at Nokia and was involved in the development of KHTML, and later at Apple as one of the developers of Safari. Currently, the Ladybird project is in the pre-alpha stage, suitable only for developer use. Initially, the project was created as an application for the SerenityOS operating system, but last summer it was spun off into a separate project and received a $1 million donation. The browser is written in C++ (planned to transition to Swift) and is distributed under the BSD license. The project is developing its own engine LibWeb, JavaScript interpreter LibJS, and related libraries.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster