The image decoder in WebKit before r52833, as used in Google Chrome before 4.0.249.78, does not properly handle a failure of memory allocation, which allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed GIF file that specifies a large size.
- http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs
No PoCs found on GitHub currently.