Fix UAF in ScriptPromiseProperty caused by reentrant code
v8::Promise::Resolve can run user code synchronously, which caused a UAF in ScriptPromiseProperty. Fix it. Bug: 1108518 Change-Id: Ia9baec6eef0887323cd88ceb1d3fa0c14fdb77ef Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2325499Reviewed-by:Yuki Shiino <yukishiino@chromium.org> Commit-Queue: Yutaka Hirano <yhirano@chromium.org> Cr-Commit-Position: refs/heads/master@{#792661}
Showing
Please register or sign in to comment