The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishandles certain array-buffer data structures, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site. <a href"http://cwe.mitre.org/data/definitions/416.html">CWE-416: Use After Free</a>
Publication date: Tue, 30 Oct 2018 21:27:00 +0000