Chromium V8 JavaScriptÒýÇæÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2021-04-130x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-04-13 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
¿ËÈÕ£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±ÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖеÄV8 JavaScriptÒýÇæÖз¢Ã÷ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£
ChromeɳÏäÊÇä¯ÀÀÆ÷µÄÇå¾²½çÏߣ¬£¬£¬£¬£¬¿É±ÜÃâÔ¶³Ì´úÂëÖ´ÐÐÎó²îÔÚÖ÷»úÉÏÆô¶¯³ÌÐò£¬£¬£¬£¬£¬¸ÃÎó²îµ¥¶ÀʹÓÃʱÏÖÔÚÎÞ·¨ÌÓÒÝä¯ÀÀÆ÷µÄɳÏ䣬£¬£¬£¬£¬Òò´Ë¸ÃÎó²îÐèÒªÓëÁíÒ»¸öÎó²îÁ´½ÓÔÚÒ»ÆðÀ´Ê¹Ó㬣¬£¬£¬£¬×îÖÕ¿ÉÒÔʵÏÖɳÏäÌÓÒÝ¡£¡£¡£
¸ÃÎó²îµÄPoCÒѹûÕæ£¬£¬£¬£¬£¬ÈôÊÇÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖмÓÔØPoC HTMLÎļþ¼°Æä¶ÔÓ¦µÄJavaScriptÎļþ£¬£¬£¬£¬£¬Ëü½«Ê¹ÓôËÎó²îÆô¶¯WindowsÅÌËãÆ÷£¨calc.exe£©³ÌÐò¡£¡£¡£
Ó°Ïì¹æÄ£
Google Chrome 89.0.4389.114(ÒѲâÊÔ)
Microsoft Edge 89.0.774.76(ÒѲâÊÔ)
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¸ÃÎó²îÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾ÖÐÐÞ¸´£¬£¬£¬£¬£¬µ«Éв»ÇåÎúºÎʱÐû²¼£¬£¬£¬£¬£¬½¨Ò鹨עGoogle¹Ù·½Ðû²¼µÄÇå¾²¸üС£¡£¡£
¹Ù·½Á´½Ó£º
https://chromereleases.googleblog.com/search/label/Stable%20updates
0x03 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/google-chrome-microsoft-edge-zero-day-vulnerability-shared-on-twitter/
https://twitter.com/r4j0x00/status/1381643526010597380
https://github.com/r4j0x00/exploits/tree/master/chrome-0day
0x04 ʱ¼äÏß
2021-04-13 PoC¹ûÕæ
2021-04-13 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/