Issue metadata
Sign in to add a comment
|
Heap-use-after-free in ScopedObserver<OmniboxPopupModel, OmniboxPopupModelObserver>::~ScopedObserver |
||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5254208342458368 Fuzzer: meacer_extension_apis Job Type: mac_asan_chrome Platform Id: mac Crash Type: Heap-use-after-free READ 8 Crash Address: 0x61200027e540 Crash State: ScopedObserver<OmniboxPopupModel, OmniboxPopupModelObserver>::~ScopedObserver - object_cxxDestructFromClass Sanitizer: address (ASAN) Recommended Security Severity: Critical Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=464662:464726 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94uQsRGMG0sspk9p6D25CAOtQwzK5RqfRxnT92CMSTOLw01Z7rRNdtVj4525GPZRdNGGC0CrPh_Bb5xfDQJ0qs6s0j4HBbHOQK3gyaIV2HJKpAHH7zTbkLG7eVlOMw0XwVuk_VbCv9bPOcZ4_IKXJjmD4YgKfgbmqiGqDreT7rMnyoJ-421nCDT6-hnlI6WSudBJmMzL--HleS3xnPuiSMH_JJbUyEGUXa6M2OP1v1M6F6_EbPkLYrannXKNbMHKx43YeaNCOhOx2iIFBVqHjJ2H_HhkhcLsdto7spGxqVJAiMRL8vRetyIAIecopIvz_BUD2H1YJ-ZSkb4mnApZjRtAciD6qgPAOT9Df2JPn_r5U_sVSk?testcase_id=5254208342458368 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 15 2017
ClusterFuzz testcase 5254208342458368 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Apr 15 2017
,
Jul 22 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 28
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ClusterFuzz
, Apr 15 2017