Issue metadata
Sign in to add a comment
|
Out-of-bounds read in Promise
Reported by
l.dmxcsn...@gmail.com,
Apr 10 2018
|
||||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.181 Safari/537.36 Steps to reproduce the problem: 1. open poc.html 2. the brower will alert the JIT address, which filled with 0x90 3. jump into JIT and crash after nops What is the expected behavior? What went wrong? Remote Code Execution in Chrome renderer process Did this work before? N/A Chrome version: 65.0.3325.181 Channel: stable OS Version: 10.0 Flash Version:
,
Apr 10 2018
ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://clusterfuzz.com/testcase?key=5996294548750336.
,
Apr 10 2018
Clusterfuzz didn't crash on this test case, but reproducing it manually does crash in Chrome 65 (Didn't seem to crash in 66 or 67). See crash/8490d341974e437a
,
Apr 11 2018
Also couldn't repro on >65, but could on 65. Assigning to clemensh, since this looks like a V8 issue.
,
Apr 12 2018
This crashes in generated code. Assigning to Bmeurer because it seems to be Promise-related.
,
Apr 12 2018
Also crashes in Node 8 if you extract the JavaScript and change the alert(this) to console.log(this). Looks like there's charCodeAt involved. sigurds@ can you please take a look?
,
Apr 12 2018
,
Apr 12 2018
,
Apr 12 2018
,
Apr 12 2018
Upgrading to High severity, given it's RCE
,
Apr 13 2018
This seems to affect Node.js as well, although I don't it is a security issue for Node as the trust model is that local JavaScript is trusted. I propose that we port the fix to Node *after* they have been fixed and released for the browser. This affects Node.js 8.x, 9.x (both using V8 6.2). I cannot reproduce this with Node.js master (V8 6.6). Does this not affect V8 6.6+?
,
Apr 13 2018
The affected code is no longer present starting with V8 6.6.
,
Apr 13 2018
,
Apr 13 2018
I think I accidentally removed the M-65 label. Adding it back.
,
Apr 18 2018
,
Apr 18 2018
,
Apr 23 2018
,
Apr 27 2018
I'm sorry to say the VRP panel declined to reward, as we didn't make any change because of this report, per comment 13.
,
Jun 20 2018
,
Jun 26 2018
,
Jul 25
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 Deleted