-
CVSS Score
-The vulnerability stems from missing CrossSite::MarshalVar wrappers when returning objects across context boundaries. The patch explicitly adds marshalling to these getter functions, which prevents access to stale object references after context closure. The exploit PoC specifically demonstrates this via DataView.buffer, and the CWE-787 (OOB write) likely manifests via corruption of these unmarshalled objects' memory.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| Microsoft.ChakraCore | nuget | < 1.8.4 | 1.8.4 |
A Semantic Attack on Google Gemini - Read the Latest Research