The flaw is in the Just-in-Time (JIT) compiler for JavaScript (the source of the browser's claimed JavaScript performance improvements), which can be put into the corrupt state, which ...could be exploited by an attacker to run arbitrary code such as installing malware..