i just started to analysis this function, interesting....https://twitter.com/pwn_expoit/status/1237404487469260801 …
-
-
yeah, i figured out the theory about the out-of-bound store and load mode in reduce element access, it's interesting, thanks for the blog, i got a deeper understanding about `reduce jsload/storeproperty` , and if needed i'll write a analysis of this new mitigation.
-
New conversation -
-
-
They started with this commit last year : https://chromium-review.googlesource.com/c/v8/v8/+/1460461 … It's interesting to see that now there are changes in BuildElementAccess and ReduceJSCreateArray (as
@pwn_expoit tweeted about)Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
With this commit, V8 has become more resistable against typer bugs.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
