Chromium V8 JavaScriptÒýÇæÔ¶³Ì´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2021-04-13

0x00 ·ì϶¸ÅÊö

CVE  ID


ʱ    ¼ä

2021-04-13

Àà   ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

½üÈÕ£¬£¬£¬£¬£¬£¬ £¬°²È«×êÑÐÈËÔ±ÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖеÄV8 JavaScriptÒýÇæÖз¢ÏÖÁËÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£

ChromeɳÏäÊÇä¯ÀÀÆ÷µÄ°²È«Ììǵ£¬£¬£¬£¬£¬£¬ £¬¿ÉÔ¤·ÀÔ¶³Ì´úÂëÖ´Ðзì϶ÔÚÖ÷»úÉÏÆô¶¯·¨Ê½£¬£¬£¬£¬£¬£¬ £¬¸Ã·ì϶µ¥¶ÀÀûÓÃʱĿǰÎÞ·¨ÌÓÒÝä¯ÀÀÆ÷µÄɳÏ䣬£¬£¬£¬£¬£¬ £¬Òò¶ø¸Ã·ì϶±ØÒªÓëÁíÒ»¸ö·ì϶Á´½ÓÔÚһ·À´ÀûÓ㬣¬£¬£¬£¬£¬ £¬×îÖÕÄܹ»ÊµÏÖɳÏäÌÓÒÝ¡£¡£¡£¡£¡£

¸Ã·ì϶µÄPoCÒѹ«¿ª£¬£¬£¬£¬£¬£¬ £¬ÈôÊÇÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖмÓÔØPoC HTMLÎļþ¼°Æä¶ÔÓ¦µÄJavaScriptÎļþ£¬£¬£¬£¬£¬£¬ £¬Ëü½«ÀûÓô˷ì϶Æô¶¯WindowsÍÆËãÆ÷£¨calc.exe£©·¨Ê½¡£¡£¡£¡£¡£

image.png

 

Ó°ÏìÁìÓò

Google Chrome 89.0.4389.114(ÒѲâÊÔ)

Microsoft Edge 89.0.774.76(ÒѲâÊÔ)

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶ÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾Öн¨¸´£¬£¬£¬£¬£¬£¬ £¬µ«Éв»Ã÷ÏÔºÎʱ°ä²¼£¬£¬£¬£¬£¬£¬ £¬½¨Ò鹨עGoogle¹Ù·½°ä²¼µÄ°²È«¸üС£¡£¡£¡£¡£

¹Ù·½Á´½Ó£º

https://chromereleases.googleblog.com/search/label/Stable%20updates

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/google-chrome-microsoft-edge-zero-day-vulnerability-shared-on-twitter/

https://twitter.com/r4j0x00/status/1381643526010597380

https://github.com/r4j0x00/exploits/tree/master/chrome-0day

 

0x04 ¹¦·òÏß

2021-04-13  PoC¹«¿ª

2021-04-13  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png