Fixed Issue #7492534


May 9, 2016
This issue is public.
Steps to reproduce


<style>body{animation-name:a}@keyframes a{0%{font:menu

I have multiple slightly different repros that lead to crashes with slightly different stacks, but all these appear to have the same root cause, so I won’t upload them all.

At first glance this may appear to be a security issue, as the code reads from an apparently arbitrary address. However, it turns out the code attempts to use a NULL pointer in a function call that is protected with Control Flow Guard (CFG) mitigations. The CFG code attempts to lookup the function address in a table, but since there is no memory allocated at address 0, no memory is allocated for that part of the table either, causing the access violation. The memory at this address is reserved however, so CFG cannot be bypassed by attempting to allocate memory there under an attackers control.


  • We are showing this as fixed with builds higher than 14374.14374.  Thank you for your feedback.

