Chrome |¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-15

0x00 Îó²î¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Ó°Ïì¹æÄ£

Chrome

CVE-2020-6454

ÄÚ´æÆÆËð

¸ßΣ

ÊÇ

Chrome < 81.0.4044.92

Chrome

CVE-2020-6423

ÄÚ´æÆÆËð

¸ßΣ

ÊÇ

Chrome < 81.0.4044.92

Chrome

CVE-2020-6455

»º³åÇøÒç³ö

¸ßΣ

ÊÇ

Chrome < 81.0.4044.92


0x01 Îó²îÏêÇé


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Google ChromeÊÇÃÀ¹ú¹È¸è£¨Google£©¹«Ë¾µÄÒ»¿îWebä¯ÀÀÆ÷¡£¡£ ¡£¡£¡£¡£¡£

2020Äê4ÔÂ7ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬GoogleÐû²¼ÁËChrome 81°æ±¾£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨32¸öÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬£¬£¬ÓÐ3¸ö±»ÆÀΪ¸ßΣ£¬ £¬£¬£¬£¬£¬£¬£¬ÏêϸÈçÏ£º

CVE-2020-6454ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾Öб£´æUAFÎó²î¡£¡£ ¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÓÕʹÓû§×°ÖöñÒâÀ©Õ¹À´Ê¹ÓôËÎó²î£¬ £¬£¬£¬£¬£¬£¬£¬½øÒ»²½Ö´ÐÐí§Òâ´úÂë»òÔì³É¾Ü¾øÐ§ÀÍ¡£¡£ ¡£¡£¡£¡£¡£

CVE-2020-6423 ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖеÄaudio±£´æUAFÎó²î¡£¡£ ¡£¡£¡£¡£¡£audioÊÇÆäÖеÄÒ»¸öÒôƵ×é¼þ¡£¡£ ¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÈ«ÐÄÖÆ×÷µÄHTMLÒ³ÃæÀ´Ê¹ÓôËÎó²î£¬ £¬£¬£¬£¬£¬£¬£¬½øÒ»²½Ö´ÐÐí§Òâ´úÂë»òÔì³É¾Ü¾øÐ§ÀÍ¡£¡£ ¡£¡£¡£¡£¡£

CVE-2020-6855 ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖеÄWebSQL±£´æ»º³åÇø¹ýʧÎó²î¡£¡£ ¡£¡£¡£¡£¡£WebSQLÊÇÆäÖеÄÒ»¸öÓÃÓÚ½«Êý¾Ý´æ´¢ÔÚÊý¾Ý¿âÖеÄÍøÒ³API£¨Ó¦ÓóÌÐò±à³Ì½Ó¿Ú£©¡£¡£ ¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÈ«ÐÄÖÆ×÷µÄHTMLÒ³ÃæÀ´Ê¹ÓôËÎó²î£¬ £¬£¬£¬£¬£¬£¬£¬½øÒ»²½Ö´ÐÐí§Òâ´úÂë»òÔì³É¾Ü¾øÐ§ÀÍ¡£¡£ ¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡£¬ £¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html


0x03 Ïà¹ØÐÂÎÅ


https://securityaffairs.co/wordpress/101334/security/firefox-chrome-browsers-flaws.html


0x04 ²Î¿¼Á´½Ó


https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html

https://nvd.nist.gov/vuln/detail/CVE-2020-6454

https://nvd.nist.gov/vuln/detail/CVE-2020-6423

https://nvd.nist.gov/vuln/detail/CVE-2020-6455


0x05 ʱ¼äÏß


2020-04-07 Chrome¹Ù·½Ðû²¼Îó²î

2020-04-13 CVEÐû²¼¸ÃÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾