BitsLab reveals another critical vulnerability in TON virtual machine and receives official thanks

2025/07/09 17:51

PANews reported on July 9 that BitsLab disclosed that its security team TonBit recently discovered a null pointer dereference vulnerability in the INMSGPARAM instruction in the TON virtual machine (TVM) v2025.04 version. Attackers can trigger the virtual machine crash by constructing special message parameters. The vulnerability was proactively reported by TonBit before the launch of TVM11 and was officially fixed and thanked. The root cause of the vulnerability is that the as_tuple() function did not perform a null pointer check. TonBit emphasized that it will continue to strengthen TVM security protection to ensure the stability of on-chain contract execution.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.