Fix the integer overflow in ChromeClientImpl::ViewportToScreen
This CL uses CheckedNumeric to avoid UBSAN issue of the integer overflow when calculating rect coordinates in ChromeClientImpl::ViewportToScreen. Fuzzer report: https://clusterfuzz.com/testcase-detail/4895093060861952 Bug: 1067114 Change-Id: Ibe0b4f353d06885024b915afedf22c125ee595d5 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2134178Reviewed-by:Kentaro Hara <haraken@chromium.org> Commit-Queue: Miyoung Shin <myid.shin@igalia.com> Cr-Commit-Position: refs/heads/master@{#756188}
Showing
Please register or sign in to comment