DevTools: context menu triggers out-of-bounds DCHECK |
||||
Issue descriptionThis might affect production and trigger UAF. Regressed in r561540, which made it to M68 cut. DCHECK is here: https://cs.chromium.org/chromium/src/third_party/blink/public/platform/web_vector.h?rcl=2fd473c99670501614888556098e9cb0de6a3139&l=166
,
Jun 4 2018
,
Jun 4 2018
approved - branch:3440
,
Jun 4 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/83423a06cb97d689429ccbf1ca7915d45121b54c commit 83423a06cb97d689429ccbf1ca7915d45121b54c Author: Dmitry Gozman <dgozman@chromium.org> Date: Mon Jun 04 23:19:48 2018 [DevTools] Fix DCHECK triggering in custom context menu TBR=dgozman@chromium.org (cherry picked from commit 25e61876da9f60fccdf679bd05ecc041d6518625) Bug: 848492 Change-Id: I84c86f60e5719186c7317d3b30d756dadd7a09d3 Reviewed-on: https://chromium-review.googlesource.com/1081560 Reviewed-by: Kentaro Hara <haraken@chromium.org> Commit-Queue: Dmitry Gozman <dgozman@chromium.org> Cr-Original-Commit-Position: refs/heads/master@{#563501} Reviewed-on: https://chromium-review.googlesource.com/1086288 Reviewed-by: Dmitry Gozman <dgozman@chromium.org> Cr-Commit-Position: refs/branch-heads/3440@{#177} Cr-Branched-From: 010ddcfda246975d194964ccf20038ebbdec6084-refs/heads/master@{#561733} [modify] https://crrev.com/83423a06cb97d689429ccbf1ca7915d45121b54c/third_party/blink/renderer/bindings/core/v8/custom/v8_dev_tools_host_custom.cc |
||||
►
Sign in to add a comment |
||||
Comment 1 by bugdroid1@chromium.org
, Jun 1 2018