|
Google Chrome contains a flaw in the 'SVGFilterPrimitiveStandardAttributes::svgAttributeChanged' function [WebCore/svg/SVGFEDisplacementMapElement.cpp] that is triggered as SVG displacement map fails to properly validate channel selections. This results in an out-of-bounds read that causes a crash.
|