Chrome |¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-15

0x00 ·ì϶¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Chrome

CVE-2020-6454

ÄÚ´æ·ÛËé

¸ßΣ

ÊÇ

Chrome < 81.0.4044.92

Chrome

CVE-2020-6423

ÄÚ´æ·ÛËé

¸ßΣ

ÊÇ

Chrome < 81.0.4044.92

Chrome

CVE-2020-6455

»º³åÇøÒç³ö

¸ßΣ

ÊÇ

Chrome < 81.0.4044.92


0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Google ChromeÊÇÃÀ¹ú¹È¸è£¨Google£©¹«Ë¾µÄÒ»¿îWebä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£¡£

2020Äê4ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬Google°ä²¼ÁËChrome 81°æ±¾£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬32¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬ÓÐ3¸ö±»ÆÀΪ¸ßΣ£¬£¬£¬£¬£¬£¬¾ßÌåÈçÏ£º

CVE-2020-6454ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖдæÔÚUAF·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÓÕʹÓû§×°ÖöñÒâÀ©´óÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬½øÒ»²½Ö´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£

CVE-2020-6423 ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖеÄaudio´æÔÚUAF·ì϶¡£¡£¡£¡£¡£¡£¡£¡£audioÊÇÆäÖеÄÒ»¸öÒôƵ×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¾«ÐÄÔì×÷µÄHTMLÒ³ÃæÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬½øÒ»²½Ö´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£

CVE-2020-6855 ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖеÄWebSQL´æÔÚ»º³åÇøÃýÎó·ì϶¡£¡£¡£¡£¡£¡£¡£¡£WebSQLÊÇÆäÖеÄÒ»¸öÓÃÓÚ½«Êý¾Ý´æ´¢ÔÚÊý¾Ý¿âÖеÄÍøÒ³API£¨ÀûÓ÷¨Ê½±à³Ì½Ó¿Ú£©¡£¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¾«ÐÄÔì×÷µÄHTMLÒ³ÃæÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬½øÒ»²½Ö´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£


0x02 ´ëÖý¨Òé


³§ÉÌÒѰ䲼Éý¼¶²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html


0x03 ÓйØÐÂÎÅ


https://securityaffairs.co/wordpress/101334/security/firefox-chrome-browsers-flaws.html


0x04 ²Î¿¼Á´½Ó


https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html

https://nvd.nist.gov/vuln/detail/CVE-2020-6454

https://nvd.nist.gov/vuln/detail/CVE-2020-6423

https://nvd.nist.gov/vuln/detail/CVE-2020-6455


0x05 ¹¦·òÏß


2020-04-07 Chrome¹Ù·½°ä²¼·ì϶

2020-04-13 CVE°ä²¼¸Ã·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website