CVE-2025-46687 | QuickJS/QuickJS-ng JS_ReadString heap-based overflow (Issue 399)
A vulnerability was found in QuickJS and QuickJS-ng. It has been declared as critical. Affected by this vulnerability is the function JS_ReadString. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2025-46687. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.