AISLE discovered a stack buffer overflow in Firefox’s WebAssembly engine that evaded detection for six months despite shipping with its own regression test. The vulnerability, CVE-2025-13016, enabled arbitrary code execution through a single line of incorrect pointer arithmetic, affecting over 180 million Firefox users worldwide.
You must log in or register to comment.
affected all Firefox versions from 143 through early 145, and Firefox ESR versions before 140.5
They praised WebAssembly so hard but it’s obviously such a dangerous vector.




