Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://crbug.com/1144368 | permissions required vendor advisory |
https://chromereleases.googleblog.com/2020/11/chrome-for-android-update.html | vendor advisory |