Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-13764. PoCs published by HaboobLab.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2019-13764, a type confusion vulnerability in V8. The exploit leverages a JIT optimization bug to achieve arbitrary read/write primitives and executes shellcode in a RWX WebAssembly page to spawn a shell.
Description
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Exploits (1)
This repository contains a functional exploit for CVE-2019-13764, a type confusion vulnerability in V8. The exploit leverages a JIT optimization bug to achieve arbitrary read/write primitives and executes shellcode in a RWX WebAssembly page to spawn a shell.
References (10)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H