Chromeä¯ÀÀÆ÷×îÐÂ0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-11-04

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13720£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Chrome < 78.0.3904.87°æ±¾¡£¡£¡£¡£¡£¡£¡£


Îó²î¸ÅÊö


Google ChromeÊÇÃÀ¹ú¹È¸è£¨Google£©¹«Ë¾µÄÒ»¿îWebä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£Google ChromeµÄÌØµãÊǾ«Á·¡¢¿ìËÙ¡£¡£¡£¡£¡£¡£¡£Google ChromeÖ§³Ö¶à±êÇ©ä¯ÀÀ£¬£¬£¬£¬Ã¿¸ö±êÇ©Ò³Ãæ¶¼ÔÚ×ÔÁ¦µÄ¡°É³Ï䡱ÄÚÔËÐУ¬£¬£¬£¬ÔÚÌá¸ßÇå¾²ÐÔµÄͬʱ£¬£¬£¬£¬Ò»¸ö±êÇ©Ò³ÃæµÄÍß½âÒ²²»»áµ¼ÖÂÆäËû±êÇ©Ò³Ãæ±»¹Ø±Õ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Google Chrome»ùÓÚ¸üǿʢµÄJavaScript V8ÒýÇæ£¬£¬£¬£¬ÕâÊÇÄ¿½ñWebä¯ÀÀÆ÷ËùÎÞ·¨ÊµÏֵġ£¡£¡£¡£¡£¡£¡£


¿ËÈÕÍâÑóÇå¾²³§ÉÌ¿¨°Í˹»ù·¢Ã÷ÁËÔÚÒ°µÄChrome 0 dayÎó²î£¬£¬£¬£¬Êܺ¦ÕßÒ»µ©»á¼û°üÀ¨Îó²îjsµÄÕ¾µã¾Í»á±»¶ñÒâ×°Öó¤ÆÚÐÔºóÃÅ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓøÃ0dayÎó²î£¬£¬£¬£¬¿É¶ÔδʹÓÃChromeä¯ÀÀÆ÷×îа汾µÄÓû§Ôì³É¶ñÒâ¹¥»÷£¬£¬£¬£¬Êܺ¦ÕßµçÄԻᱻװÖó¤ÆÚÐÔºóÃÅ£¬£¬£¬£¬ÉõÖÁ»áÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬ÓÉÓÚChromeÓû§Á¿Õ¼±ÈºÜ´ó£¬£¬£¬£¬ÒÔÊÇÔì³ÉµÄΣº¦Ó°ÏìºÜ´ó¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞEXP/POC¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


Éý¼¶ChromeÖÁ78.0.3904.87°æ±¾¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/