TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Google Chrome Zero Day CVE-2021-4102, Use after free in V8

82 pointsby excerionsforteover 3 years ago

5 comments

vitusover 3 years ago
IMO the most important line in that blog post is:<p>&gt; Google is aware of reports that an exploit for CVE-2021-4102 exists in the wild.
评论 #29561978 未加载
iechoz6Hover 3 years ago
Pretty useless page if you are interested in details;<p>link [1] is a search query for `type:bug-security os=Android,ios,linux,mac,windows,all,chrome label:Release-2-M96` which returns no result from `bugs.chromium.org`<p>link [2] is a generic Chrome landing page<p>links [3-7] require Google Login (WTF?)<p>I gave up after that.<p>Edit; I actually didn&#x27;t give up, I searched `<a href="https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;chromium&#x2F;issues&#x2F;list" rel="nofollow">https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;chromium&#x2F;issues&#x2F;list</a>` for the associated issue numbers with no results.<p>1. <a href="https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;chromium&#x2F;issues&#x2F;list?can=1&amp;q=type%3Abug-security+os%3DAndroid%2Cios%2Clinux%2Cmac%2Cwindows%2Call%2Cchrome+label%3ARelease-2-M96" rel="nofollow">https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;chromium&#x2F;issues&#x2F;list?can=1&amp;q=typ...</a><p>2. <a href="https:&#x2F;&#x2F;sites.google.com&#x2F;a&#x2F;chromium.org&#x2F;dev&#x2F;Home&#x2F;chromium-security" rel="nofollow">https:&#x2F;&#x2F;sites.google.com&#x2F;a&#x2F;chromium.org&#x2F;dev&#x2F;Home&#x2F;chromium-se...</a><p>3. <a href="https:&#x2F;&#x2F;crbug.com&#x2F;1263457" rel="nofollow">https:&#x2F;&#x2F;crbug.com&#x2F;1263457</a><p>4. <a href="https:&#x2F;&#x2F;crbug.com&#x2F;1270658" rel="nofollow">https:&#x2F;&#x2F;crbug.com&#x2F;1270658</a><p>5. <a href="https:&#x2F;&#x2F;crbug.com&#x2F;1272068" rel="nofollow">https:&#x2F;&#x2F;crbug.com&#x2F;1272068</a><p>6. <a href="https:&#x2F;&#x2F;crbug.com&#x2F;1262080" rel="nofollow">https:&#x2F;&#x2F;crbug.com&#x2F;1262080</a><p>7. <a href="https:&#x2F;&#x2F;crbug.com&#x2F;1278387" rel="nofollow">https:&#x2F;&#x2F;crbug.com&#x2F;1278387</a>
评论 #29563283 未加载
thekashifmalikover 3 years ago
This is one class of bugs that would not exist if V8 was written in Rust.
评论 #29562620 未加载
评论 #29562427 未加载
josephscottover 3 years ago
How does this impact v8 based services, like Cloudflare Workers?
评论 #29562146 未加载
评论 #29563313 未加载
评论 #29562616 未加载
akomtuover 3 years ago
Well, if you&#x27;re using an adblock with JS disabled, you may sleep well.
评论 #29562189 未加载
评论 #29562389 未加载
评论 #29562412 未加载