Overview

Medium
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
ImpactUse after free in V8
DescriptionUse after free in V8
ComponentV8
Bug ClassUAF
Tracker498818402
Fix commit533bed9f375d (v8/v8) +5/-1
CISA KEVNot listed
CreditedGoogle
Disclosed2026-06-02

Changed Functions

FunctionChangeNotes
WasmMemoryMapDescriptor
src/objects/objects-body-descriptors-inl.h
modified

Files Changed

  • src/objects/objects-body-descriptors-inl.h
From 533bed9f375d7663d99273ab3a9b4843bcde9928 Mon Sep 17 00:00:00 2001
From: Andreas Haas <[email protected]>
Date: Wed, 15 Apr 2026 06:59:04 -0700
Subject: [PATCH] [wasm] Iterate all references of WasmMemoryMapDescriptor

The WasmMemoryMapDescriptor is a subclass of JSObject, and therefore has
to iterate all potential outgoing references of JSObject.

The CL was made by CodeMender.

Bug: 498818402
Change-Id: I20199d492e4f5ca15f7176d2b76fe5b13f7ae150
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7761131
Commit-Queue: Andreas Haas <[email protected]>
Reviewed-by: Anton Bikineev <[email protected]>
Cr-Commit-Position: refs/heads/main@{#106530}
---

diff --git a/src/objects/objects-body-descriptors-inl.h b/src/objects/objects-body-descriptors-inl.h
index 9d5d3bd..ba8a917 100644
--- a/src/objects/objects-body-descriptors-inl.h
+++ b/src/objects/objects-body-descriptors-inl.h
@@ -1077,11 +1077,15 @@
   }
 };
 
-class WasmMemoryMapDescriptor::BodyDescriptor : public BodyDescriptorBase {
+class WasmMemoryMapDescriptor::BodyDescriptor final : public BodyDescriptorBase {
  public:
+  template <typename ObjectVisitor>
   static inline void IterateBody(Tagged<Map> map, Tagged<HeapObject> obj,
                                  int object_size, ObjectVisitor* v) {
+    IteratePointers(obj, JSObject::BodyDescriptor::kStartOffset, kMemoryOffset,
+                    v);
     IterateMaybeWeakPointer(obj, kMemoryOffset, v);
+    IterateJSObjectBodyImpl(map, obj, kHeaderSize, object_size, v);
   }
 
   static inline int SizeOf(Tagged<Map> map, Tagged<HeapObject> object) {
Loading diff…

Original Bug Report

reported by [email protected]

Crash in v8::internal::Heap::Contains

Detailed Report: https://clusterfuzz.com/testcase?key=6602752981499904

Fuzzer: big_sleep Job Type: linux_asan_d8_dbg Platform Id: linux

Crash Type: UNKNOWN READ Crash Address: 0x77cd01040000 Crash State: v8::internal::Heap::Contains v8::internal::HeapObject::VerifyHeapPointer v8::internal::TorqueGeneratedClassVerifiers::JSReceiverVerify

Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_dbg&range=103388:103389

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6602752981499904

Issue filed automatically.

To reproduce this, please build the target in this report and run it against the reproducer testcase. Please use the GN arguments provided at bottom of this report when building the binary.

If you have trouble reproducing, please also export the environment variables listed under “[Environment]” in the crash stacktrace.

If you have any feedback on reproducing test cases, let us know at https://forms.gle/Yh3qCYFveHj6E5jz5 so we can improve.

View on issue tracker