Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's a different bug (CVE-2024-0517 vs CVE-2024-0519)


I’m pretty sure the chain is all three bugs. 517, 518, 519.


I'm pretty sure it isn't, the write up only uses 517 to get an arbitrary write primitive and then did a pretty standard chain into a sandbox escape via wasm (disclaimer - I work on V8).


Hmm. I also thought the type confusion in 518 was the same one from the blog post, but looking at the patch, it's not either. I think I stand corrected overall.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: