FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Vieb -- Remote Code Execution via Visiting Untrusted URLs

Affected packages
linux-vieb < 12.4.0

Details

VuXML ID aaa060af-88d6-11f0-a294-b0416f0c4c67
Discovery 2025-07-31
Entry 2025-09-03

Zhengyu Liu, Jianjia Yu, Jelmer van Arnhem report:

We discovered a remote code execution (RCE) vulnerability in the latest release of the Vieb browser (v12.3.0). By luring a user to visit a malicious website, an attacker can achieve arbitrary code execution on the victim’s machine.

References

URL https://github.com/Jelmerro/Vieb/security/advisories/GHSA-h2fq-667q-7gpm