apparently v8 has a value just called TheHole
-
apparently v8 has a value just called TheHole
-
R AodeRelay shared this topic
-
apparently v8 has a value just called TheHole
@0x57e11a@void.lgbt I know about this only from its role in a big JIT vuln a while back lol
-
@0x57e11a@void.lgbt I know about this only from its role in a big JIT vuln a while back lol
@hazelnoot JSON.stringify, or?
-
@hazelnoot JSON.stringify, or?
@0x57e11a@void.lgbt I don't recall the details, only that it involved obtaining a direct reference to TheHole and then manipulating it to induce a double-free somewhere
-
@0x57e11a@void.lgbt I don't recall the details, only that it involved obtaining a direct reference to TheHole and then manipulating it to induce a double-free somewhere
@hazelnoot this is the JSON.stringify vuln it found https://issues.chromium.org/issues/40057710