Google Chrome v8 Web Assembly Type Confusion

Strike ID:
E18-m9x71
CVSS:
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2017

Description

This strike exploits a vulnerability in the Google Chrome browser. Specifically, the vulnerability exists in Javascript v8 engine. It is possible to craft Javascript in such a way that when the main thread parses the WebAssembly Code, the worker thread can also modify this code at the same time causing out of bounds memory access. This may lead to a denial of service condition in the browser, or potentially remote code execution.

CVE

Google

Bid