vendor:
Safari
by:
Project Zero
6,5
CVSS
MEDIUM
Use-after-free
416
CWE
Product Name: Safari
Affected Version From: Safari 10.0.2
Affected Version To: Safari 10.0.2
Patch Exists: Yes
Related CWE: CVE-2017-5090
CPE: a:apple:safari:10.0.2
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac
2017
Frame::setDocument Vulnerability
This vulnerability is a use-after-free vulnerability in the Frame::setDocument function. It occurs when a frame is set to a new document, and then the unload event handler is called. If the frame is set to a new document again in the unload event handler, the prepareForDestruction function is never called, which means the frame will never be detached from the new document. This can be exploited by setting the frame to a malicious page in the unload event handler, which can then execute arbitrary code.
Mitigation:
The best way to mitigate this vulnerability is to ensure that the prepareForDestruction function is called before setting the frame to a new document.