Browser

Memory Corruption

WebKit - AXObjectCache - m_deferredFocusedNodeChange - UaF

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

9.8
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS31
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-10018
VENDORS
WebKit (Apple)
PUBLIC EXPLOIT
None indexed
CWE
CWE-416
PRODUCT
WebKit
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in WebKit. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the sandboxed browser.

Vulnerability details

Vulnerability details

CVE-2020-10018
CWE-416
Critical | 9.8

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code. A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in WebKit.

Auth:
None (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2019-11-19 Reported to vendor on bugs.webkit.org

2020-03-12 Coordinated public release of Advisory

Credits

Sudhakar Verma, Ashfaq Ansari & Siddhant Badhe – Project Srishti of CloudFuzz.