From object transition to RCE in the Chrome renderer

In this post, I’ll exploit CVE-2024-5830, a type confusion bug in v8, the Javascript engine of Chrome that I reported in May 2024 as bug 342456991. The bug was fixed in version 126.0.6478.56/57.

Source: Github

 


Date:

Categorie(s):