The bug was assigned CVE-2025-2135, and we successfully used it to pwn Google’s V8CTF as a zero-day. The root cause lies in TurboFan’s InferMapsUnsafe() function, which fails to handle aliasing when ...
Abstract: Software engineers can do tasks of maintenance and evolution of complex software systems only after they understand well the existing code. Our goal is to build automatic tools to help ...