-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| Microsoft.ChakraCore | nuget | < 1.10.1 | 1.10.1 |
The GitHub patch adds critical bounds checks to both functions. The commit message explicitly states ServerAddDOMFastPathHelper was vulnerable to being called with bad arguments, leading to OOB reads in GetMethodOriginalAddress. The vulnerability occurs when an attacker-controlled 'helper' value propagates through ServerAddDOMFastPathHelper to the helper method array access in GetMethodOriginalAddress, bypassing CFG protections by redirecting execution flow.
A Semantic Attack on Google Gemini - Read the Latest Research