{ "dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": { "cveId": "CVE-2025-62492", "assignerOrgId": "14ed7db2-1595-443d-9d34-6215bf890778", "state": "PUBLISHED", "assignerShortName": "Google", "dateReserved": "2025-10-15T08:47:41.878Z", "datePublished": "2025-10-16T15:51:34.445Z", "dateUpdated": "2025-10-16T18:02:02.585Z" }, "containers": { "cna": { "affected": [ { "collectionURL": "https://bellard.org/quickjs/", "defaultStatus": "unaffected", "packageName": "js_typed_array_indexOf", "product": "QuickJS", "vendor": "QuickJS", "versions": [ { "lessThan": "2025-09-13", "status": "affected", "version": "2025-04-26", "versionType": "date" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "Google Big Sleep" } ], "datePublic": "2025-07-24T22:00:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "
A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation of TypedArray.prototype.indexOf() when a negative fromIndex argument is supplied.
The fromIndex argument (read as a double variable, $d$) is used to calculate the starting position for the search.
If d is negative, the index is calculated relative to the end of the array by adding the array's length (len) to d:
Due to the inherent limitations of floating-point arithmetic, if the negative value $d$ is extremely small (e.g., $-1 \\times 10^{-20}$), the addition $d + \\text{len}$ can result in a loss of precision, yielding an outcome that is exactly equal to $\\text{len}$.
The result is then converted to an integer index $k$: $k = \\text{len}$.
The search function proceeds to read array elements starting from index $k$. Since valid indices are $0$ to $\\text{len}-1$, starting the read at index $\\text{len}$ is one element past the end of the array.