Chromium V8 JavaScriptÒýÇæÔ¶³Ì´úÂëÖ´ÐЩ¶´

Ðû²¼Ê±¼ä 2021-04-13

0x00 ©¶´¸ÅÊö

CVE  ID


ʱ    ¼ä

2021-04-13

Àà   ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

image.png

 

½üÈÕ£¬Äþ¾²Ñо¿ÈËÔ±ÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖеÄV8 JavaScriptÒýÇæÖз¢ÏÖÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´ ¡£

ChromeɳÏäÊÇä¯ÀÀÆ÷µÄÄþ¾²½çÏÞ£¬¿É·ÀÖ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´ÔÚÖ÷»úÉÏÆô¶¯·¨Ê½£¬¸Ã©¶´µ¥¶ÀÀûÓÃʱĿǰÎÞ·¨ÌÓÒÝä¯ÀÀÆ÷µÄɳÏ䣬Òò´Ë¸Ã©¶´ÐèÒªÓëÁíÒ»¸ö©¶´Á´½ÓÔÚÒ»ÆðÀ´ÀûÓã¬×îÖÕ¿ÉÒÔʵÏÖɳÏäÌÓÒÝ ¡£

¸Ã©¶´µÄPoCÒѹûÈ»£¬Èç¹ûÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖмÓÔØPoC HTMLÎļþ¼°Æä¶ÔÓ¦µÄJavaScriptÎļþ£¬Ëü½«ÀûÓôË©¶´Æô¶¯Windows¼ÆËãÆ÷£¨calc.exe£©·¨Ê½ ¡£

image.png

 

Ó°Ï췶Χ

Google Chrome 89.0.4389.114(ÒѲâÊÔ)

Microsoft Edge 89.0.774.76(ÒѲâÊÔ)

 

0x02 ´¦Öý¨Òé

Ŀǰ¸Ã©¶´ÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾ÖÐÐÞ¸´£¬µ«Éв»Çå³þºÎʱÐû²¼£¬½¨Ò鹨עGoogle¹Ù·½Ðû²¼µÄÄþ¾²¸üР¡£

¹Ù·½Á´½Ó£º

https://chromereleases.googleblog.com/search/label/Stable%20updates

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/google-chrome-microsoft-edge-zero-day-vulnerability-shared-on-twitter/

https://twitter.com/r4j0x00/status/1381643526010597380

https://github.com/r4j0x00/exploits/tree/master/chrome-0day

 

0x04 ʱ¼äÏß

2021-04-13  PoC¹ûÈ»

2021-04-13  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png