¡¾Îó²îͨ¸æ¡¿Google Chrome V8 ÀàÐÍ»ìÏýÎó²î (CVE-2025-6554)

Ðû²¼Ê±¼ä 2025-07-02

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Google Chrome V8 ÀàÐÍ»ìÏýÎó²î

CVE   ID

CVE-2025-6554

Îó²îÀàÐÍ

ÀàÐÍ»ìÏýÎó²î

·¢Ã÷ʱ¼ä

2025-07-02

Îó²îÆÀ·Ö

8.1

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Google Chrome ÊÇÓɹȸ迪·¢µÄ¿çÆ½Ì¨ÍøÒ³ä¯ÀÀÆ÷ £¬£¬£¬ÒÔÆäËÙÂÊ¡¢Çå¾²ÐԺ;«Á·µÄ½çÃæ¶øÖøÃû¡£¡£¡£¡£¡£¡£Ëü»ùÓÚ¿ªÔ´µÄChromiumÏîÄ¿ £¬£¬£¬Ö§³ÖÏÖ´úÍøÒ³±ê×¼ £¬£¬£¬¾ßÓÐǿʢµÄÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£ChromeµÄɳÏäÊÖÒÕ¿ÉÒÔÏÞÖÆÍøÒ³ÖеĶñÒâ´úÂë £¬£¬£¬ÔöÇ¿ä¯ÀÀÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£Ëü»¹ÌṩÁËͬ²½¹¦Ð§ £¬£¬£¬ÔÊÐíÓû§ÔÚ¶à¸ö×°±¸¼äͬ²½ÊéÇ©¡¢ÀúÊ·¼Í¼µÈÊý¾Ý¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬Chrome°´ÆÚ¸üР£¬£¬£¬ÐÞ¸´ÒÑÖªÎó²î²¢ÔöÇ¿¹¦Ð§ £¬£¬£¬ÊÇÈ«ÇòʹÓÃ×îÆÕ±éµÄä¯ÀÀÆ÷Ö®Ò»¡£¡£¡£¡£¡£¡£


2025Äê7ÔÂ2ÈÕ £¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½ChromeÐû²¼µÄÇ徲ͨ¸æ £¬£¬£¬Ö¸³öGoogle Chrome 138.0.7204.96¼°Ö®Ç°°æ±¾ÖеÄV8ÀàÐÍ»ìÏýÎó²î£¨CVE-2025-6554£©¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýÈ«ÐĽṹµÄHTMLÒ³ÃæÖ´ÐÐí§Òâ¶Á/д²Ù×÷¡£¡£¡£¡£¡£¡£GoogleÒÑÖª¸ÃÎó²îÒѱ»¶ñÒâʹÓà £¬£¬£¬Îó²îÆÀ·ÖΪ8.1·Ö £¬£¬£¬Îó²î¼¶±ðΪ¸ßΣ¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁÐÞ¸´°æ±¾ £¬£¬£¬ÒÔ×èֹDZÔÚΣº¦¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Google Chrome(Windows) < 138.0.7204.96/.97
Google Chrome(MacOS) < 138.0.7204.92/.93
Google Chrome(Linux) < 138.0.7204.96¡£¡£¡£¡£¡£¡£


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾ £¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://www.google.cn/chrome/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


?°´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬£¬£¬ïÔ̭ϵͳÎó²î £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£
?ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
?ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£
?ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£

?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.html
https://nvd.nist.gov/vuln/detail/CVE-2025-6554