Google Chrome contains a race condition in the 'CrossCallParamsEx::CreateFromBuffer' function in sandbox/src/crosscall_server.cc checking and using IPC lengths. With a specially crafted web page, a context-dependent attacker can potentially read and write data inside the broker process, bypassing the sandbox.
Classification
Location:
Context Dependent
Attack Type:
Race Condition
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade to version 18.0.1025.168 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.