Chrome StoragePartitionService Double-Destruction Race
Posted by deepcore on March 20, 2019 – 9:40 pm
There’s a race condition in the destruction of the BindingState for bindings to the StoragePartitionService in Chrome. It looks like the root cause of the issue is that since we can get two concurrent calls to callbacks returned from mojo::BindingSet::GetBadMessageCallback() from the same BindingSet, which results in a data race destroying the same BindingState.
Post a reply
You must be logged in to post a comment.