New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 702437 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 702058
Owner: ----
Closed: Mar 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Mac
Pri: 1
Type: Bug-Security



Sign in to add a comment

<no crash state available>

Project Member Reported by ClusterFuzz, Mar 16 2017

Issue description

Project Member

Comment 1 by ClusterFuzz, Mar 17 2017

Labels: OS-Android
Labels: OS-Mac
Crashes Chrome Canary 59.0.3043.0 and 57.0.2987.0 on OS X.

https://crash.corp.google.com/browse?q=reportid=%27d1d5bf1480000000%27
crashme.html
190 bytes View Download
<script>
arr = [];
for (let i = 0; i < 49079; i++) arr[i] = [];
unk = {valueOf: function() { arr.length = 0; }};
arr.indexOf({}, unk);
</script>

Interestingly, the repro seems to be sensitive to the upper-bound value of the loop, and it crashes with a slightly lower top-bound on Canary than on Stable. 
Project Member

Comment 4 by sheriffbot@chromium.org, Mar 17 2017

Labels: FoundIn-M-58 FoundIn-M-57 Fracas
Users experienced this crash on the following builds:

Mac Dev 58.0.3029.19 -  0.63 CPM, 3 reports, 3 clients (signature v8::internal::`anonymous namespace'::Invoke)
Linux Beta 57.0.2987.98 -  1.16 CPM, 30 reports, 22 clients (signature v8::internal::`anonymous namespace'::Invoke)

If this update was incorrect, please add "Fracas-Wrong" label to prevent future updates.

- Go/Fracas
Components: Blink>JavaScript
This appears to be a pure JavaScript problem, no DOM involvement.
Heh. Isn't this just  Issue 702058 ?
Project Member

Comment 7 by sheriffbot@chromium.org, Mar 17 2017

Labels: FoundIn-M-59
Users experienced this crash on the following builds:

Mac Canary 59.0.3043.0 -  0.82 CPM, 4 reports, 4 clients (signature v8::internal::`anonymous namespace'::Invoke)
Linux Beta 57.0.2987.98 -  1.15 CPM, 31 reports, 22 clients (signature v8::internal::`anonymous namespace'::Invoke)

If this update was incorrect, please add "Fracas-Wrong" label to prevent future updates.

- Go/Fracas
Project Member

Comment 8 by sheriffbot@chromium.org, Mar 17 2017

Labels: Pri-1

Comment 9 by tsepez@chromium.org, Mar 17 2017

Mergedinto: 702058
Status: Duplicate (was: Untriaged)
I concur.  
Cc: manoranj...@chromium.org
Cc: ligim...@chromium.org
Project Member

Comment 13 by sheriffbot@chromium.org, Jun 25 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment