At first i was wondering how one can get RCE out of double-free and then author proceed to drop a bomb - android would reliably return same adress to the next two allocations of same size as freed memory. Android behaviour here is simply unacceptable. One would expect (yeah) memory managment bugs from user space applications, but return same memory from a default allocator twice because of double-free is a terrible peculiarity, undefined behavour or not.
umanwizard|6 years ago
tedunangst|6 years ago
shaklee3|6 years ago
not2b|6 years ago
nothrabannosir|6 years ago
lubesGordi|6 years ago
gpderetta|6 years ago