vendor:
Chrome
by:
Vladimir Vorontsov
8,8
CVSS
HIGH
Use-after-free vulnerability
416
CWE
Product Name: Chrome
Affected Version From: 28.0.1461.0
Affected Version To: 28.0.1461.0
Patch Exists: YES
Related CWE: CVE-2014-1743
CPE: a:google:chrome:28.0.1461.0
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2014
Object-Beforeload-Chrome.html
A use-after-free vulnerability exists in Chromium release build 28.0.1461.0 (191833) due to a lack of proper validation of user-supplied input. An attacker can exploit this vulnerability to execute arbitrary code in the context of the browser. The vulnerability is triggered when a maliciously crafted HTML page is loaded in the browser, which causes a memory corruption in the 'WebCore::RenderWidget::updateWidgetGeometry()' function. This can be exploited to execute arbitrary code by spraying the heap with a specially crafted Uint8ClampedArray object.
Mitigation:
Upgrade to the latest version of Chromium.