There is a heap overflow in Skia when drawing paths with anti-aliasing turned off. This issue can be triggered in both Google Chrome and Mozilla Firefox by rendering a specially crafted SVG image. Proof of concepts included.
3f160181c8497dc4cf1f1145b96c07f641ce5f7ac700a9824ddcbbf59315795b
Debian Linux Security Advisory 4237-1 - Several vulnerabilities have been discovered in the chromium web browser.
87dfa3d834f2c582296fcb795eb91850f979b0960217effc608d092e66e389cd
Red Hat Security Advisory 2018-2112-01 - Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 60.1.0 ESR. Issues addressed include buffer overflow, cross site request forgery, and use-after-free vulnerabilities.
c83b51fc510827e3da5f97c2bdaefb75707217c460d8a14d5c67b9cf283e90fa
Red Hat Security Advisory 2018-2113-01 - Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 60.1.0 ESR. Issues addressed include buffer overflow, cross site request forgery, and use-after-free vulnerabilities.
733eefe7a714bfbb481e79af2fb8c94cc9b1e0409edce093a2e253f22750db8e
Ubuntu Security Notice 3682-1 - A heap buffer overflow was discovered in Skia. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service, or execute arbitrary code.
494f9b017be16951b96c87f973088ab519f111541e946ab28bd1de038e9136ed
Debian Linux Security Advisory 4220-1 - Ivan Fratric discovered a buffer overflow in the Skia graphics library used by Firefox, which could result in the execution of arbitrary code.
20dac8da2aa3b0850230e9839582a70df5eb615fb9c785abfc18ecae374e9b7d
Red Hat Security Advisory 2018-1815-01 - Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 67.0.3396.62. Issues addressed include buffer overflow and bypass vulnerabilities.
8f57ce73f4ddf5a4287d9acccf2d60250bcada5d5d6f932a11ac26b81f6dce4a