Chromeä¯ÀÀÆ÷×îÐÂ0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-11-04

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13720£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Chrome < 78.0.3904.87°æ±¾¡£


Îó²î¸ÅÊö


Google ChromeÊÇÃÀ¹ú¹È¸è£¨Google£©¹«Ë¾µÄÒ»¿îWebä¯ÀÀÆ÷¡£Google ChromeµÄÌØµãÊǾ«Á·¡¢¿ìËÙ¡£Google ChromeÖ§³Ö¶à±êÇ©ä¯ÀÀ£¬Ã¿¸ö±êÇ©Ò³Ãæ¶¼ÔÚ×ÔÁ¦µÄ¡°É³Ï䡱ÄÚÔËÐУ¬ÔÚÌá¸ßÇå¾²ÐÔµÄͬʱ£¬Ò»¸ö±êÇ©Ò³ÃæµÄÍß½âÒ²²»»áµ¼ÖÂÆäËû±êÇ©Ò³Ãæ±»¹Ø±Õ¡£±ðµÄ£¬Google Chrome»ùÓÚ¸üǿʢµÄJavaScript V8ÒýÇæ£¬ÕâÊÇÄ¿½ñWebä¯ÀÀÆ÷ËùÎÞ·¨ÊµÏֵġ£


¿ËÈÕÍâÑóÇå¾²³§ÉÌ¿¨°Í˹»ù·¢Ã÷ÁËÔÚÒ°µÄChrome 0 dayÎó²î£¬Êܺ¦ÕßÒ»µ©»á¼û°üÀ¨Îó²îjsµÄÕ¾µã¾Í»á±»¶ñÒâ×°Öó¤ÆÚÐÔºóÃÅ¡£¹¥»÷ÕßʹÓøÃ0dayÎó²î£¬¿É¶ÔδʹÓÃChromeä¯ÀÀÆ÷×îа汾µÄÓû§Ôì³É¶ñÒâ¹¥»÷£¬Êܺ¦ÕßµçÄԻᱻװÖó¤ÆÚÐÔºóÃÅ£¬ÉõÖÁ»áÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬ÓÉÓÚChromeÓû§Á¿Õ¼±ÈºÜ´ó£¬ÒÔÊÇÔì³ÉµÄΣº¦Ó°ÏìºÜ´ó¡£


Îó²îÑéÖ¤


ÔÝÎÞEXP/POC¡£


ÐÞ¸´½¨Òé


Éý¼¶ChromeÖÁ78.0.3904.87°æ±¾¡£


²Î¿¼Á´½Ó


https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/