WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
The product does not correctly convert an object, resource, or structure from one type to a different type.
Link | Tags |
---|---|
https://bugs.chromium.org/p/chromium/issues/detail?id=76784 | mailing list exploit vendor advisory |
http://trac.webkit.org/changeset/81648 | mailing list patch vendor advisory |
http://trac.webkit.org/changeset/81748 | mailing list patch vendor advisory |