A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Blink | * | m12 (excluding) | |
| Qtwebkit | Ubuntu | trusty | * |
| Qtwebkit-opensource-src | Ubuntu | trusty | * |
| Qtwebkit-source | Ubuntu | trusty | * |
| Webkitgtk | Ubuntu | trusty | * |