CVE-2025-62492: Heap out-of-bounds read in js_typed_array_indexOf in QuickJS

Published Oct 16, 2025
·
Updated

A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation of TypedArray.prototype.indexOf() when a negative fromIndex argument is supplied.

The fromIndex argument (read as a double variable, $d$) is used to calculate the starting position for the search.

If d is negative, the index is calculated relative to the end of the array by adding the array's length (len) to d:

$$d{new} = d + \text{len}$$

Due to the inherent limitations of floating-point arithmetic, if the negative value $d$ is extremely small (e.g., $-1 \times 10^{-20}$), the addition $d + \text{len}$ can result in a loss of precision, yielding an outcome that is exactly equal to $\text{len}$.

The result is then converted to an integer index $k$: $k = \text{len}$.

The search function proceeds to read array elements starting from index $k$. Since valid indices are $0$ to $\text{len}-1$, starting the read at index $\text{len}$ is one element past the end of the array.

This allows an attacker to cause an Out-of-Bounds Read of one element immediately following the buffer. While the scope of this read is small (one element), it can potentially lead to Information Disclosure of adjacent memory contents, depending on the execution environment.

Affected Software

2 affected components
QuickJS QuickJS
Quickjs Project Quickjs<2025-09-13

Event History

Oct 16, 2025
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-62492?

CVE-2025-62492 is classified as a moderate severity vulnerability due to potential impacts on application correctness.

2

How do I fix CVE-2025-62492?

To fix CVE-2025-62492, update to the latest version of the QuickJS engine that addresses the floating-point precision error.

3

Who is affected by CVE-2025-62492?

CVE-2025-62492 affects applications using the QuickJS engine with the TypedArray.prototype.indexOf() function.

4

What type of vulnerability is CVE-2025-62492?

CVE-2025-62492 is a vulnerability caused by floating-point arithmetic precision errors in QuickJS.

5

Can CVE-2025-62492 lead to security issues?

While CVE-2025-62492 primarily affects data correctness, it may indirectly lead to security issues if relied upon in security-critical applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203