The bug was assigned CVE-2025-2135, and we successfully used it to pwn Google’s V8CTF as a zero-day. The root cause lies in TurboFan’s InferMapsUnsafe() function, which fails to handle aliasing when ...
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works. The V8 JavaScript compiler is an important part of these efforts as it takes the JavaScript found ...