CVE-2024-2887: A Pwn2Own Winning Bug in Google Chrome
ID: 511e658f-bfa3-5c74-bff9-7a2813019386
STIX ID: report--511e658f-bfa3-5c74-bff9-7a2813019386
Feed Name: Zero Day Initiative (ZDI) Blog
Threat Score
The report analyzes a V8 WebAssembly/typed-array vulnerability where abusing a HeapType::kNone type-index alias permits arbitrary reference-type transmutation, yielding primitives for arbitrary read/write and fake object/address-of operations; combined with an integer-underflow in TypedArray length computation for resizable/growable buffers, this enables escaping the V8 memory sandbox and achieving powerful exploitation primitives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
