Safari Proxy Object Type Confusion

Discussion in 'News Aggregator' started by Packet Storm, 14 Dec 2018.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a type confusion bug in the Javascript Proxy object in WebKit. The DFG JIT does not take into account that, through the use of a Proxy, it is possible to run arbitrary JS code during the execution of a CreateThis operation. This makes it possible to change the structure of e.g. an argument without causing a bailout, leading to a type confusion.

    Continue reading...
     

Share This Page

Loading...