CVE-2018-16071
HIGHGoogle Chrome < 69.0.3497.81 - Use-After-Free in WebRTC via Crafted Video File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-16071. PoCs published by Google Security Research.
AI-analyzed exploit summary This is a detailed writeup describing a use-after-free vulnerability in WebRTC's VP9 processing, specifically in the RtpFrameReferenceFinder::ManageFrameVp9 method. The analysis includes ASAN output showing the heap-use-after-free condition triggered by manipulating tl0_pic_idx in incoming packets.
Description
A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
Exploits (1)
This is a detailed writeup describing a use-after-free vulnerability in WebRTC's VP9 processing, specifically in the RtpFrameReferenceFinder::ManageFrameVp9 method. The analysis includes ASAN output showing the heap-use-after-free condition triggered by manipulating tl0_pic_idx in incoming packets.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H