Google Project Zero published several vulnerability reports covering memory-safety and type-confusion flaws in major JavaScript engines, including Mozilla SpiderMonkey, Google V8, and Apple JavaScriptCore. The issues described unsafe conditions such as leaked JS_OPTIMIZED_OUT values, V8 map migration that failed to respect element kinds and caused type confusion, incorrect garbage-collection assumptions in JavaScriptCore's DFG pipeline, unsafe ObjectGroup handling in SpiderMonkey's IonMonkey, and a JavaScriptCore CodeBlock use-after-free tied to dangling watchpoints.
Project Zero also disclosed a macOS sandbox escape involving type confusion in coreaudiod and the CoreAudio framework, extending the set of reports beyond browser engines into operating-system security boundaries. Taken together, the disclosures highlight recurring exploitation risks from type confusion, use-after-free, and JIT/compiler logic errors that can enable unsafe code execution, memory corruption, or sandbox bypass across widely deployed platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Google Project Zero published issue 372511888 describing a macOS sandbox escape via type confusion in coreaudiod and the CoreAudio framework.
Google Project Zero published issue 1923 describing a V8 flaw where Map migration does not respect element kind, leading to type confusion.
Google Project Zero published issue 1808 describing a SpiderMonkey IonMonkey issue where an unexpected ObjectGroup in ObjectGroupDispatch could lead to potentially unsafe code execution.
Google Project Zero published issue 1802 describing an error in JavaScriptCore DFG's doesGC() handling of HasIndexedProperty on StringObjects.
Google Project Zero published issue 1794 describing a SpiderMonkey IonMonkey flaw that leaks the JS_OPTIMIZED_OUT magic value to script.
Google Project Zero published issue 1783 describing a JavaScriptCore CodeBlock use-after-free caused by dangling watchpoints.
6 references tracked. Mallory keeps watching after this page renders.
project-zero.issues.chromium.org
Open sourcebugs.chromium.org
Open sourcebugs.chromium.org
Open sourcebugs.chromium.org
Open sourcebugs.chromium.org
Open sourcebugs.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.