
JSC JIT Out-Of-Bounds Access

The DFG and FTL JIT compilers incorrectly replace Checked with Unchecked ArithNegate operations (and vice versa) during Common Subexpression Elimination. This can then be exploited to cause out-of-bounds accesses and potentially other memory safety violations.

No Comment.

Add Your Comment

You must be logged in to post a comment.