Google Chrome contains a race condition flaw in the 'AudioOutputController::DoFlush' function [media/audio/audio_output_controller.cc] that is triggered when handling audio. With a specially crafted web page, a context dependent attacker can crash the browser and potentially execute arbitrary code.
Classification
Location:
Remote / Network Access
Attack Type:
Race Condition
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade to version 9.0.597.84 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.