WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome prior to 49.0.2623.75, does not properly determine when anonymous block wrappers may exist, which allows remote malicious users to cause a denial of service (incorrect cast and assertion failure) or possibly have unspecified other impact via crafted JavaScript code.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
google chrome |