#VU25897 Out-of-bounds read in ChakraCore and Microsoft Edge - CVE-2020-0813
Published: March 10, 2020
ChakraCore
Microsoft Edge
Microsoft
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing untrusted data in Chakra scripting engine. A remote attacker who knows the memory address of where the object was created can trigger out-of-bounds read error and read contents of memory on the system.