Chrome suffers from a type confusion vulnerability in JSPromise::TriggerPromiseReactions. Continue reading...