Chromium V8 JavaScriptÒýÇæÔ¶³Ì´úÂëÖ´ÐЩ¶´
Ðû²¼Ê±¼ä 2021-04-130x00 ©¶´¸ÅÊö
CVE ID | ʱ ¼ä | 2021-04-13 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
PoC/EXP | ÒѹûÈ» | ÔÚÒ°ÀûÓà |
0x01 ©¶´ÏêÇé
½üÈÕ£¬Äþ¾²Ñо¿ÈËÔ±ÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖеÄV8 JavaScriptÒýÇæÖз¢ÏÖÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£
ChromeɳÏäÊÇä¯ÀÀÆ÷µÄÄþ¾²½çÏÞ£¬¿É·ÀÖ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´ÔÚÖ÷»úÉÏÆô¶¯·¨Ê½£¬¸Ã©¶´µ¥¶ÀÀûÓÃʱĿǰÎÞ·¨ÌÓÒÝä¯ÀÀÆ÷µÄɳÏ䣬Òò´Ë¸Ã©¶´ÐèÒªÓëÁíÒ»¸ö©¶´Á´½ÓÔÚÒ»ÆðÀ´ÀûÓã¬×îÖÕ¿ÉÒÔʵÏÖɳÏäÌÓÒÝ¡£
¸Ã©¶´µÄPoCÒѹûÈ»£¬Èç¹ûÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖмÓÔØPoC HTMLÎļþ¼°Æä¶ÔÓ¦µÄJavaScriptÎļþ£¬Ëü½«ÀûÓôË©¶´Æô¶¯Windows¼ÆËãÆ÷£¨calc.exe£©·¨Ê½¡£
Ó°Ï췶Χ
Google Chrome 89.0.4389.114(ÒѲâÊÔ)
Microsoft Edge 89.0.774.76(ÒѲâÊÔ)
0x02 ´¦Öý¨Òé
Ŀǰ¸Ã©¶´ÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾ÖÐÐÞ¸´£¬µ«Éв»Çå³þºÎʱÐû²¼£¬½¨Ò鹨עGoogle¹Ù·½Ðû²¼µÄÄþ¾²¸üС£
¹Ù·½Á´½Ó£º
https://chromereleases.googleblog.com/search/label/Stable%20updates
0x03 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/google-chrome-microsoft-edge-zero-day-vulnerability-shared-on-twitter/
https://twitter.com/r4j0x00/status/1381643526010597380
https://github.com/r4j0x00/exploits/tree/master/chrome-0day
0x04 ʱ¼äÏß
2021-04-13 PoC¹ûÈ»
2021-04-13 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/