Chrome GPU Process BufferManager Double Reads

The GPU buffer manager doesn’t handle pointers to shared memory with adequate care, allowing an attacker to bypass chrome’s validation and pass invalid buffer data to the hosting OpenGL implementation.

Leave a Reply