Firing a slider event can detach the current AXObject.
In response to an accessibility action to change the value of a slider, we fire a DOM event. However, firing that DOM event can result in arbitrary user code being called, which can mean detaching the current AXObject, leading to a crash/UAF. Fix this by checking after firing a DOM event. Bug: 1079445 Change-Id: Ic16b9a5312a14e57bc56a9c8124ffe64d1b69f65 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2211930 Commit-Queue: Dominic Mazzoni <dmazzoni@chromium.org> Reviewed-by:Meredith Lane <meredithl@chromium.org> Cr-Commit-Position: refs/heads/master@{#772443}
Showing
Please register or sign in to comment