Security
Headlines
HeadlinesLatestCVEs

Headline

Chrome LinkToTextMenuObserver::CompleteWithError Heap Use-After-Free

A use-after-free issue exists in Chrome 104 and earlier versions. Processing maliciously crafted web content may lead to arbitrary code execution in the browser process. LinkToTextMenuObserver holds a raw pointer to a RenderFrameHost object, but is not owned by the frame host and does not watch for frame host destruction events. Therefore, if an attacker manages to destroy the frame host right after the observer is created but before the timeout task posted in StartLinkGenerationRequestWithTimeout() is executed, use-after-free will occur.

Packet Storm
#web#chrome

© 2022 Packet Storm. All rights reserved.

Packet Storm: Latest News

Ubuntu Security Notice USN-7089-6