Google Chrome Blink Component Integer Overflow

Strike ID:
E16-6zy01
CVSS:
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2016

Description

This strike exploits a vulnerability in the Google Chrome Blink component. The vulnerability is due to an integer overflow that occurs in the ImageBitmap function when processing a createImageBitmap function with overly large width and height values. When the ImageBitmap function copies these values into a heap buffer an overflow can occur. This can potentially allow for remote code execution.

CVE

Bid