tl;dr 2 element overflow in Array when jit compiled
tl;dr 2 element overflow in Array when jit compiled
tl;dr
Array.pop
. Uint32Array
and a Uint8Array
to get a overflow in an ArrayBuffer
and proceed to convert this to arbitrary read-write and execute shellcode.