¡¾Îó²îͨ¸æ¡¿Google Chrome V8¶Ñ»º³åÇøÒç³öÎó²î(CVE-2025-0999)

Ðû²¼Ê±¼ä 2025-02-20

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Google Chrome V8¶Ñ»º³åÇøÒç³öÎó²î

CVE   ID

CVE-2025-0999

Îó²îÀàÐÍ

»º³åÇøÒç³ö

·¢Ã÷ʱ¼ä

2025-02-20

Îó²îÆÀ·Ö

8.8

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Google Chrome V8ÊÇÒ»¸ö¸ßЧµÄ¿ªÔ´JavaScriptÒýÇæ£¬£¬£¬£¬ÓÃÓÚChromeä¯ÀÀÆ÷ºÍNode.jsµÈƽ̨¡£¡£¡£¡£V8½«JavaScript´úÂë±àÒëΪ»úеÂ룬£¬£¬£¬ÒÔÌá¸ßÖ´ÐÐЧÂÊ£¬£¬£¬£¬ÓÅ»¯ä¯ÀÀÆ÷ÐÔÄÜ¡£¡£¡£¡£ËüÖ§³Ö¼´Ê±±àÒ루JIT£©ºÍÀ¬»ø½ÓÄÉ»úÖÆ£¬£¬£¬£¬Í¨¹ýÄÚ´æÖÎÀíºÍÓÅ»¯Ëã·¨Ìṩ¸üºÃµÄÔËÐÐËÙÂÊ¡£¡£¡£¡£V8ÆÕ±éÓÃÓÚÍøÒ³ºÍÓ¦ÓóÌÐòÖУ¬£¬£¬£¬ÓÈÆäÔÚ´¦Öóͷ£ÖØ´óµÄ¶¯Ì¬ÄÚÈÝʱÌåÏÖÓÅÔ½¡£¡£¡£¡£¸ÃÒýÇæµÄ¸ßЧÐÔÊÇChromeä¯ÀÀÆ÷Á÷ͨÌåÑéµÄÖ÷ÒªÒòËØÖ®Ò»¡£¡£¡£¡£


2025Äê2ÔÂ20ÈÕ£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½GoogleÐû²¼Á˹ØÓÚCVE-2025-0999Îó²îµÄÇ徲ͨ¸æ¡£¡£¡£¡£Í¨¸æÖ¸³ö£¬£¬£¬£¬Google Chromeä¯ÀÀÆ÷ÖÐV8ÒýÇæ±£´æ¶Ñ»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìChrome 133.0.6943.126֮ǰµÄ°æ±¾£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâµÄHTMLÒ³Ãæ£¬£¬£¬£¬Ê¹ÓøÃÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼Ö¶ÑÄÚ´æÆÆË𡣡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8·Ö£¬£¬£¬£¬Îó²îÆ·¼¶Îª¸ßΣ¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Google Chrome < 133.0.6943.126


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


½¨ÒéÊÜÓ°Ïì°æ±¾µÄÓû§¾¡¿ìÉý¼¶µ½ÒÔϰ汾£¬£¬£¬£¬ÒÔ½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£
Google Chrome °æ±¾ 133.0.6943.126 (Windows¡¢Mac)
Google Chrome °æ±¾ 133.0.6943.127 (Windows¡¢Mac)
Google Chrome °æ±¾ 133.0.6943.126 (Linux)


ÏÂÔØÁ´½Ó£º

https://www.google.cn/intl/zh-CN/chrome/


3.2 ÔÝʱ²½·¥



ÔÝÎÞ¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_18.html
https://issues.chromium.org/issues/394350433
https://nvd.nist.gov/vuln/detail/CVE-2025-0999