Chrome V8 JIT JSBuiltinReducer::ReduceObjectCreate NULL Check Fail

Chrome V8 JIT JSBuiltinReducer::ReduceObjectCreate fails to ensure that the prototype is “null”.

Leave a Reply