GeistHaus
log in · sign up

From object transition to RCE in the Chrome renderer

github.blog

In this post, I'll exploit CVE-2024-5830, a type confusion in Chrome that allows remote code execution (RCE) in the renderer sandbox of Chrome by a single visit to a malicious site.

1 page links to this URL