Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
PoC: CVE-2019-11707
Exploit code for CVE-2019-11707 on Firefox 66.0.3 running on Ubuntu
PoC: cve-2019-11707
https://bugs.chromium.org/p/project-zero/issues/detail?id=1820
PoC: CVE-2019-11707-from-an-IonMonkey-type-confusion-to-SYSTEM-
CVE-2019-11707 is a critical type confusion in Firefox's IonMonkey optimizing JIT. The browser bug provides native code execution in the content process, but that process remains constrained by the Firefox sandbox. The complete laboratory chain therefore combines three vulnerabilities:
PoC: CVE-2019-11707-PoC
Proof of concept for CVE-2019-11707
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free