|
WebKit contains a typecasting flaw in the 'RenderLayerBacking::startAnimation' function in WebCore/rendering/RenderLayerBacking.cpp when starting an accelerated transform animation on a renderer. With a specially crafted web page, a context-dependent attacker can corrupt memory to cause a denial of service or potentially execute arbitrary code.
|