0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

More than 5 years have passed since last update.

[漏洞通告]CVE-2020-6418/Chrome V8类型混淆利用堆内存破坏导致远程代码执行漏洞

Posted at

漏洞描述

V8Google Chrome的开源JavaScriptWebAssembly引擎。Google Chrome80.0.3987.122版本前,V8的实现中存在类型混淆漏洞,可导致堆内存破坏,使得攻击者可非法访问数据,利用精心制作的html,可达到恶意代码执行的效果.该漏洞已被在野利用多时,已经为第三次被捕获的Chrome的0day.

漏洞编号

CVE-2020-6418

漏洞威胁等级

高危

影响范围

<= 80.0.3987.122

漏洞验证

测试的Chrome版本为80.0.3987.122,OS为macOS 10.15.2
image.png
模拟攻击者,部署恶意html页面在web服务器,访问恶意html页面触发弹出Chrome内置打印机
image.png

修复建议

更新Chrome到最新版本

时间轴

[0] 2020/02/27 NVD发布漏洞通告
[1] 2020/03/05 亚信安全网络攻防实验室分析&复现该漏洞并发布漏洞通告

Reference

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
https://github.com/ray-cp/browser_pwn/tree/master/cve-2020-6418
https://mp.weixin.qq.com/s/cLZ7Jv2p9wlK87qN03TRqA

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?