Chromeä¯ÀÀÆ÷×îÐÂ0dayÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-11-04Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-13720£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Chrome < 78.0.3904.87°æ±¾¡£
Îó²î¸ÅÊö
Google ChromeÊÇÃÀ¹ú¹È¸è£¨Google£©¹«Ë¾µÄÒ»¿îWebä¯ÀÀÆ÷¡£Google ChromeµÄÌØµãÊǾ«Á·¡¢¿ìËÙ¡£Google ChromeÖ§³Ö¶à±êÇ©ä¯ÀÀ£¬Ã¿¸ö±êÇ©Ò³Ãæ¶¼ÔÚ×ÔÁ¦µÄ¡°É³Ï䡱ÄÚÔËÐУ¬ÔÚÌá¸ßÇå¾²ÐÔµÄͬʱ£¬Ò»¸ö±êÇ©Ò³ÃæµÄÍß½âÒ²²»»áµ¼ÖÂÆäËû±êÇ©Ò³Ãæ±»¹Ø±Õ¡£±ðµÄ£¬Google Chrome»ùÓÚ¸üǿʢµÄJavaScript V8ÒýÇæ£¬ÕâÊÇÄ¿½ñWebä¯ÀÀÆ÷ËùÎÞ·¨ÊµÏֵġ£
¿ËÈÕÍâÑóÇå¾²³§ÉÌ¿¨°Í˹»ù·¢Ã÷ÁËÔÚÒ°µÄChrome 0 dayÎó²î£¬Êܺ¦ÕßÒ»µ©»á¼û°üÀ¨Îó²îjsµÄÕ¾µã¾Í»á±»¶ñÒâ×°Öó¤ÆÚÐÔºóÃÅ¡£¹¥»÷ÕßʹÓøÃ0dayÎó²î£¬¿É¶ÔδʹÓÃChromeä¯ÀÀÆ÷×îа汾µÄÓû§Ôì³É¶ñÒâ¹¥»÷£¬Êܺ¦ÕßµçÄԻᱻװÖó¤ÆÚÐÔºóÃÅ£¬ÉõÖÁ»áÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬ÓÉÓÚChromeÓû§Á¿Õ¼±ÈºÜ´ó£¬ÒÔÊÇÔì³ÉµÄΣº¦Ó°ÏìºÜ´ó¡£
Îó²îÑéÖ¤
ÔÝÎÞEXP/POC¡£
ÐÞ¸´½¨Òé
Éý¼¶ChromeÖÁ78.0.3904.87°æ±¾¡£
²Î¿¼Á´½Ó
https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/


¾©¹«Íø°²±¸11010802024551ºÅ