logo

The hunt for Chromium issue 1072171

ID: d000b27d-3161-5626-b9ce-c702dd5dd0d3

STIX ID: report--d000b27d-3161-5626-b9ce-c702dd5dd0d3

Feed Name: SensePost Blog

Threat Score
55/100

Date Published: 2020-05-29

Date Updated: 2026-04-30

...
...

This blog post describes discovering and analyzing a V8 engine type-confusion vulnerability triggered by -0 values in Math.max/Math.min which caused the Turbofan typer to lose the MinusZero type and produce incorrect optimized code (leading to crashes and divergent behavior after optimization). The author details fuzzing setup (Fuzzilli, AFL++), instrumentation steps to target the typer, triage of crashes, debugger-assisted root-cause analysis in NumberMax/NumberMin, and the patch approach that preserves -0 in the computed types to avoid the erroneous optimization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.