JSC DFG ObjectAllocationSinkingPhase Crash

An issue in JSC leaves the data flow graph inconsistent. While fuzzing JavaScriptCore with fuzzilli, the researcher found a crash condition in JSC.

Leave a Reply