Chromium V8 JavaScriptÒýÇæÔ¶³Ì´úÂëÖ´Ðзì϶
°ä²¼¹¦·ò 2021-04-130x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-04-13 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà |
0x01 ·ì϶ÏêÇé

½üÈÕ£¬°²È«×êÑÐÈËÔ±ÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖеÄV8 JavaScriptÒýÇæÖз¢ÏÖÁËÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£
ChromeɳÏäÊÇä¯ÀÀÆ÷µÄ°²È«Ììǵ£¬¿ÉÔ¤·ÀÔ¶³Ì´úÂëÖ´Ðзì϶ÔÚÖ÷»úÉÏÆô¶¯·¨Ê½£¬¸Ã·ì϶µ¥¶ÀÀûÓÃʱĿǰÎÞ·¨ÌÓÒÝä¯ÀÀÆ÷µÄɳÏ䣬Òò¶ø¸Ã·ì϶±ØÒªÓëÁíÒ»¸ö·ì϶Á´½ÓÔÚһ·À´ÀûÓã¬×îÖÕÄܹ»ÊµÏÖɳÏäÌÓÒÝ¡£
¸Ã·ì϶µÄPoCÒѹ«¿ª£¬ÈôÊÇÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖмÓÔØPoC HTMLÎļþ¼°Æä¶ÔÓ¦µÄJavaScriptÎļþ£¬Ëü½«ÀûÓô˷ì϶Æô¶¯WindowsÍÆËãÆ÷£¨calc.exe£©·¨Ê½¡£

Ó°ÏìÁìÓò
Google Chrome 89.0.4389.114(ÒѲâÊÔ)
Microsoft Edge 89.0.774.76(ÒѲâÊÔ)
0x02 ´ëÖý¨Òé
Ŀǰ¸Ã·ì϶ÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾Öн¨¸´£¬µ«Éв»Ã÷ÏÔºÎʱ°ä²¼£¬½¨Ò鹨עGoogle¹Ù·½°ä²¼µÄ°²È«¸üС£
¹Ù·½Á´½Ó£º
https://chromereleases.googleblog.com/search/label/Stable%20updates
0x03 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/google-chrome-microsoft-edge-zero-day-vulnerability-shared-on-twitter/
https://twitter.com/r4j0x00/status/1381643526010597380
https://github.com/r4j0x00/exploits/tree/master/chrome-0day
0x04 ¹¦·òÏß
2021-04-13 PoC¹«¿ª
2021-04-13 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ