360Safe and 360Chrome browsers buffer overflow exploited

Let's focus on browsers' security.

 

Both 360Safe and 360Chrome browsers have the java rhino script engine buffer overflow vulnerability recently disclosed.

 

Attackers could exploit this vulnerability to execute arbitrary code outside of the sandbox.

 
PoC demo:
360Safe browser is not quite safe:
http://www.youtube.com/watch?v=9NRlfDe3SYQ
360Chrome also exploited:
http://www.youtube.com/watch?v=_eT-AfcpBJg