Chromium V8 JavaScriptÒýÇæÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ðû²¼Ê±¼ä 2021-04-13

0x00 Îó²î¸ÅÊö

CVE  ID


ʱ    ¼ä

2021-04-13

Àà   ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

 

¿ËÈÕ£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±ÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖеÄV8 JavaScriptÒýÇæÖз¢Ã÷ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£

ChromeɳÏäÊÇä¯ÀÀÆ÷µÄÇå¾²½çÏߣ¬£¬£¬£¬£¬¿É±ÜÃâÔ¶³Ì´úÂëÖ´ÐÐÎó²îÔÚÖ÷»úÉÏÆô¶¯³ÌÐò£¬£¬£¬£¬£¬¸ÃÎó²îµ¥¶ÀʹÓÃʱÏÖÔÚÎÞ·¨ÌÓÒÝä¯ÀÀÆ÷µÄɳÏ䣬£¬£¬£¬£¬Òò´Ë¸ÃÎó²îÐèÒªÓëÁíÒ»¸öÎó²îÁ´½ÓÔÚÒ»ÆðÀ´Ê¹Ó㬣¬£¬£¬£¬×îÖÕ¿ÉÒÔʵÏÖɳÏäÌÓÒÝ¡£¡£¡£

¸ÃÎó²îµÄPoCÒѹûÕæ£¬£¬£¬£¬£¬ÈôÊÇÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖмÓÔØPoC HTMLÎļþ¼°Æä¶ÔÓ¦µÄJavaScriptÎļþ£¬£¬£¬£¬£¬Ëü½«Ê¹ÓôËÎó²îÆô¶¯WindowsÅÌËãÆ÷£¨calc.exe£©³ÌÐò¡£¡£¡£

image.png

 

Ó°Ïì¹æÄ£

Google Chrome 89.0.4389.114(ÒѲâÊÔ)

Microsoft Edge 89.0.774.76(ÒѲâÊÔ)

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¸ÃÎó²îÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾ÖÐÐÞ¸´£¬£¬£¬£¬£¬µ«Éв»ÇåÎúºÎʱÐû²¼£¬£¬£¬£¬£¬½¨Ò鹨עGoogle¹Ù·½Ðû²¼µÄÇå¾²¸üС£¡£¡£

¹Ù·½Á´½Ó£º

https://chromereleases.googleblog.com/search/label/Stable%20updates

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/google-chrome-microsoft-edge-zero-day-vulnerability-shared-on-twitter/

https://twitter.com/r4j0x00/status/1381643526010597380

https://github.com/r4j0x00/exploits/tree/master/chrome-0day

 

0x04 ʱ¼äÏß

2021-04-13  PoC¹ûÕæ

2021-04-13  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png