|
Google Chrome contains a flaw in the 'WebGraphicsContext3DCommandBufferImpl::FlipVertically' function in content/common/gpu/client/webgraphicscontext3d_command_buffer_impl.cc when handling temporary scanlines for vertical flip. With a specially crafted web page, a context-dependent attacker can corrupt heap memory to cause a denial of service or potentially execute arbitrary code.
|