Chromeä¯ÀÀÆ÷×îÐÂ0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-11-04

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13720£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Chrome < 78.0.3904.87°æ±¾¡£


·ì϶¸ÅÊö


Google ChromeÊÇÃÀ¹ú¹È¸è£¨Google£©¹«Ë¾µÄÒ»¿îWebä¯ÀÀÆ÷¡£Google ChromeµÄÌØµãÊǼò½à¡¢¼±¾ç¡£Google ChromeÖ§³Ö¶à±êÇ©ä¯ÀÀ£¬Ã¿¸ö±êÇ©Ò³Ãæ¶¼ÔÚ¶ÀÁ¢µÄ¡°É³Ï䡱ÄÚÔËÐУ¬ÔÚÌá¸ß°²È«ÐÔµÄͬʱ£¬Ò»¸ö±êÇ©Ò³ÃæµÄ±ÀÀ£Ò²²»»áµ¼ÖÂÆäËû±êÇ©Ò³Ãæ±»¹Ø¹Ø¡£´Ë±í£¬Google Chrome»ùÓÚ¸ü׳´óµÄJavaScript V8ÒýÇæ£¬ÕâÊǵ±Ç°Webä¯ÀÀÆ÷ËùÎÞ·¨ÊµÏֵġ£


½üÈÕ¹ú±í°²È«³§ÉÌ¿¨°Í˹»ù·¢ÏÖÁËÔÚÒ°µÄChrome 0 day·ì϶£¬Êܺ¦ÕßÒ»µ©½Ó¼ûÔ̺¬·ì϶jsµÄÕ¾µã¾Í»á±»¶ñÒâ×°ÖÃÓÆ¾ÃÐÔºóÃÅ¡£¹¥»÷ÕßÀûÓøÃ0day·ì϶£¬¿É¶ÔδʹÓÃChromeä¯ÀÀÆ÷×îа汾µÄÓû§Ôì³É¶ñÒâ¹¥»÷£¬Êܺ¦ÕßµçÄԻᱻװÖÃÓÆ¾ÃÐÔºóÃÅ£¬ÉõÖÁ»áÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬ÓÉÓÚChromeÓû§Á¿Õ¼±ÈºÜ´ó£¬ËùÒÔÔì³ÉµÄ·çÏÕÓ°ÏìºÜ´ó¡£


·ì϶ÑéÖ¤


ÔÝÎÞEXP/POC¡£


½¨¸´½¨Òé


Éý¼¶ChromeÖÁ78.0.3904.87°æ±¾¡£


²Î¿¼Á´½Ó


https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/