Google Chrome Blink Serializer::doSerialize Bad Cast
Posted by deepcore on November 15, 2016 – 2:28 am
When serializing JavaScript objects for sending to another window using the postMessage method, the code in blink does not handle Symbol objects correctly and attempts to serialize this kind of object as a regular object, which results in a bad cast. An attacker that can trigger this issue may be able to execute arbitrary code. Chrome version 38 is affected.
Post a reply
You must be logged in to post a comment.