Microsoft Edge Array.splice Heap Overflow
Posted by deepcore on November 19, 2016 – 3:14 am
There is a heap overflow in Array.splice in Chakra. When an array is spliced, and overflow check is performed, but ArraySpeciesCreate, which can execute code and alter the array is called after this. This can allow an Array with boundaries that cause integer overflows to be spliced, leading to heap overflows in several situations.
Post a reply
You must be logged in to post a comment.