¡¾·ì϶¹«¸æ¡¿Google Chrome ýÌåÁ÷¿ªÊͺó³ÁÓ÷ì϶(CVE-2025-8292)

°ä²¼¹¦·ò 2025-07-31

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Google Chrome ýÌåÁ÷¿ªÊͺó³ÁÓ÷ì϶

CVE   ID

CVE-2025-8292

·ì϶ÀàÐÍ

¿ªÊͺó³ÁÓÃ

·¢ÏÖ¹¦·ò

2025-07-31

·ì϶ÆÀ·Ö

8.8

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

±ØÒª

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


Google Chrome ÊÇÓɹȸ迪·¢µÄ¿çÆ½Ì¨ÍøÒ³ä¯ÀÀÆ÷£¬ÒÔÆä¿ìÂÊ¡¢°²È«ÐԺͼò½àµÄ½çÃæ¶øÎÅÃû¡£Ëü»ùÓÚ¿ªÔ´µÄChromiumÏîÄ¿£¬Ö§³ÖÏÖ´úÍøÒ³³ß¶È£¬ÓµÓÐ׳´óµÄÀ©´óÐÔ¡£ChromeµÄɳÏä¼¼ÊõÄܹ»ÏÞ¶ÈÍøÒ³ÖеĶñÒâ´úÂ룬¼ÓÇ¿ä¯ÀÀÆ÷µÄ°²È«ÐÔ¡£Ëü»¹ÌṩÁËͬ²½Ö°ÄÜ£¬ÔÊÐíÓû§ÔÚ¶à¸öÉ豸¼äͬ²½ÊéÇ©¡¢º¹Çà¼Í¼µÈÊý¾Ý¡£´Ë±í£¬Chrome¶¨ÆÚ¸üУ¬½¨¸´ÒÑÖª·ì϶²¢¼ÓǿְÄÜ£¬ÊÇÈ«ÇòʹÓÃ×î¿í·ºµÄä¯ÀÀÆ÷Ö®Ò»¡£


2025Äê7ÔÂ31ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Chromeä¯ÀÀÆ÷´æÔÚÒ»¸ö¸ßΣ·ì϶£¨CVE-2025-8292£©£¬Ô´ÓÚMedia Stream×é¼þÖеÄuse-after-freeÄڴ濪ÊͺóʹÓÃÃýÎó¡£¹¥»÷Õß¿Éͨ¹ý»ú¹ØÌض¨Ã½ÌåÁ÷²Ù×÷ÓÕ·¢¿ªÊͺó½Ó¼û£¬Ôì³ÉÄÚ´æ·ÛË飬½ø¶ø¿ÉÄÜʵÏÖä¯ÀÀÆ÷±ÀÀ£»òÔ¶³Ì´úÂëÖ´ÐУ¬·ì϶ÆÀ·Ö8.8·Ö£¬·ì϶¼¶±ð¸ßΣ¡£


¶þ¡¢Ó°ÏìÁìÓò


Google Chrome£¨Linux£©< 138.0.7204.183
Google Chrome£¨Windows/Mac£©< 138.0.7204.183/138.0.7204.184


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


Google Chrome£¨Linux£©>= 138.0.7204.183
Google Chrome£¨Windows/Mac£©>= 138.0.7204.183/138.0.7204.184


ÏÂÔØÁ´½Ó£ºhttps://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_29.html


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


?¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
?¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
?ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
?¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_29.html