The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote attackers to cause a denial of service or possibly have unknown other impact via crafted JavaScript code.
2016-01-25T11:59:00.120
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.6 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4