Chrome Array Transfer Bypass
Posted by deepcore on May 15, 2021 – 5:21 pm
The fix for CVE-2021-21148 has added a check in |ValueSerializer::WriteJSArrayBuffer| to make sure non-detachable array buffers cannot be transferred. The check can be bypassed with the help of asm.js and property getters.
Post a reply
You must be logged in to post a comment.