Chromium V8 JavaScriptÒýÇæÔ¶³Ì´úÂëÖ´Ðзì϶
°ä²¼¹¦·ò 2021-04-130x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-04-13 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà |
0x01 ·ì϶ÏêÇé

½üÈÕ£¬£¬£¬£¬£¬£¬£¬°²È«×êÑÐÈËÔ±ÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖеÄV8 JavaScriptÒýÇæÖз¢ÏÖÁËÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£
ChromeɳÏäÊÇä¯ÀÀÆ÷µÄ°²È«Ììǵ£¬£¬£¬£¬£¬£¬£¬¿ÉÔ¤·ÀÔ¶³Ì´úÂëÖ´Ðзì϶ÔÚÖ÷»úÉÏÆô¶¯·¨Ê½£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶µ¥¶ÀÀûÓÃʱĿǰÎÞ·¨ÌÓÒÝä¯ÀÀÆ÷µÄɳÏ䣬£¬£¬£¬£¬£¬£¬Òò¶ø¸Ã·ì϶±ØÒªÓëÁíÒ»¸ö·ì϶Á´½ÓÔÚһ·À´ÀûÓ㬣¬£¬£¬£¬£¬£¬×îÖÕÄܹ»ÊµÏÖɳÏäÌÓÒÝ¡£¡£¡£¡£¡£
¸Ã·ì϶µÄPoCÒѹ«¿ª£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖмÓÔØPoC HTMLÎļþ¼°Æä¶ÔÓ¦µÄJavaScriptÎļþ£¬£¬£¬£¬£¬£¬£¬Ëü½«ÀûÓô˷ì϶Æô¶¯WindowsÍÆËãÆ÷£¨calc.exe£©·¨Ê½¡£¡£¡£¡£¡£

Ó°ÏìÁìÓò
Google Chrome 89.0.4389.114(ÒѲâÊÔ)
Microsoft Edge 89.0.774.76(ÒѲâÊÔ)
0x02 ´ëÖý¨Òé
Ŀǰ¸Ã·ì϶ÒÑÔÚV8 JavaScriptÒýÇæµÄ×îа汾Öн¨¸´£¬£¬£¬£¬£¬£¬£¬µ«Éв»Ã÷ÏÔºÎʱ°ä²¼£¬£¬£¬£¬£¬£¬£¬½¨Ò鹨עGoogle¹Ù·½°ä²¼µÄ°²È«¸üС£¡£¡£¡£¡£
¹Ù·½Á´½Ó£º
https://chromereleases.googleblog.com/search/label/Stable%20updates
0x03 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/google-chrome-microsoft-edge-zero-day-vulnerability-shared-on-twitter/
https://twitter.com/r4j0x00/status/1381643526010597380
https://github.com/r4j0x00/exploits/tree/master/chrome-0day
0x04 ¹¦·òÏß
2021-04-13 PoC¹«¿ª
2021-04-13 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ