Chrome Blink SpeechRecognitionController Use-After-Free

Discussion in 'News Aggregator' started by Packet Storm, 23 Nov 2016.

  1. Packet Storm

    Packet Storm Guest

    A specially crafted web-page can cause the blink rendering engine used by Google Chrome and Chromium to continue to use a speech recognition API object after the memory block that contained the object has been freed. An attacker can force the code to read a pointer from the freed memory and use this to call a function, allowing arbitrary code execution. Google Chrome version 39.0 is affected.

    Continue reading...
     

Share This Page

Loading...