EIP-2026-104167
PRE-CVEApple WebKit / Safari 10.0.2(12602.3.12.0.1) - 'operationSpreadGeneric' Universal Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104167. PoCs published by Google Security Research.
AI-analyzed exploit summary This PoC exploits a type confusion vulnerability in JavaScriptCore's spread operation optimization, leading to arbitrary code execution. The exploit triggers a bug where `operationSpreadGeneric` incorrectly handles the JSGlobalObject, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser.
Description
Apple WebKit / Safari 10.0.2(12602.3.12.0.1) - 'operationSpreadGeneric' Universal Cross-Site Scripting
Exploits (1)
This PoC exploits a type confusion vulnerability in JavaScriptCore's spread operation optimization, leading to arbitrary code execution. The exploit triggers a bug where `operationSpreadGeneric` incorrectly handles the JSGlobalObject, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser.