Browsing the "webkit" Tag

WebKit WebCore::FrameLoader::PolicyChecker::checkNavigationPolicy Heap Use-After-Free – Torchsec

August 19th, 2021 | ๐Ÿ•’

TTS Demo WebKit: heap-use-after-free in WebCore::FrameLoader::PolicyChecker::checkNavigationPolicy VULNERABILITY DETAILSPolicyChecker.cpp:```#define IS_ALLOWED (m_frame.page() ? m_frame.page()->sessionID().isAlwaysOnLoggingAllowed() : false)#define PAGE_ID (m_frame.loader().pageID().valueOr(PageIdentifier()).toUInt64())#define FRAME_ID (m_frame.loader().frameID().valueOr(FrameIdentifier()).toUInt64())#define RELEASE_LOG_IF_ALLOWED(fmt, ...)