CVE-2016-9651
HIGHGoogle Chrome < 55.0.2883.75 - Remote Code Execution via V8 JS Object Property Check Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-9651. PoCs published by Qihoo360.
AI-analyzed exploit summary This exploit targets a memory corruption vulnerability in V8 JavaScript engine (CVE-2016-9651) by manipulating out-of-bounds strings and heap spraying to achieve arbitrary memory read/write. It demonstrates a complex exploit chain for remote code execution in Chrome.
Description
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Exploits (1)
This exploit targets a memory corruption vulnerability in V8 JavaScript engine (CVE-2016-9651) by manipulating out-of-bounds strings and heap spraying to achieve arbitrary memory read/write. It demonstrates a complex exploit chain for remote code execution in Chrome.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H