Microsoft Edge JSON.parse Information Leak

Discussion in 'News Aggregator' started by Packet Storm, 2 Dec 2016.

  1. Packet Storm

    Packet Storm Guest

    Microsoft Edge has an information leak in JSON.parse. If this function is called with a reviver, and the reviver modifies the output object to contain a native array, the Walk function assumes that this array is a Var array, and writes pointers to it. These pointers can then be read out of the array by script.

    Continue reading...
     

Share This Page

Loading...