Chrome |¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-15

0x00 ·ì϶¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Chrome

CVE-2020-6454

ÄÚ´æ·ÛËé

¸ßΣ

ÊÇ

Chrome < 81.0.4044.92

Chrome

CVE-2020-6423

ÄÚ´æ·ÛËé

¸ßΣ

ÊÇ

Chrome < 81.0.4044.92

Chrome

CVE-2020-6455

»º³åÇøÒç³ö

¸ßΣ

ÊÇ

Chrome < 81.0.4044.92


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Google ChromeÊÇÃÀ¹ú¹È¸è£¨Google£©¹«Ë¾µÄÒ»¿îWebä¯ÀÀÆ÷¡£

2020Äê4ÔÂ7ÈÕ£¬Google°ä²¼ÁËChrome 81°æ±¾£¬ÆäÖÐÔ̺¬32¸ö°²È«·ì϶£¬ÓÐ3¸ö±»ÆÀΪ¸ßΣ£¬¾ßÌåÈçÏ£º

CVE-2020-6454ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖдæÔÚUAF·ì϶¡£Ô¶³Ì¹¥»÷Õß¿ÉÓÕʹÓû§×°ÖöñÒâÀ©´óÀ´ÀûÓô˷ì϶£¬½øÒ»²½Ö´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£

CVE-2020-6423 ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖеÄaudio´æÔÚUAF·ì϶¡£audioÊÇÆäÖеÄÒ»¸öÒôƵ×é¼þ¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¾«ÐÄÔì×÷µÄHTMLÒ³ÃæÀ´ÀûÓô˷ì϶£¬½øÒ»²½Ö´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£

CVE-2020-6855 ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖеÄWebSQL´æÔÚ»º³åÇøÃýÎó·ì϶¡£WebSQLÊÇÆäÖеÄÒ»¸öÓÃÓÚ½«Êý¾Ý´æ´¢ÔÚÊý¾Ý¿âÖеÄÍøÒ³API£¨ÀûÓ÷¨Ê½±à³Ì½Ó¿Ú£©¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¾«ÐÄÔì×÷µÄHTMLÒ³ÃæÀ´ÀûÓô˷ì϶£¬½øÒ»²½Ö´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£


0x02 ´ëÖý¨Òé


³§ÉÌÒѰ䲼Éý¼¶²¹¶¡£¬ÏÂÔØÁ´½Ó£º

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html


0x03 ÓйØÐÂÎÅ


https://securityaffairs.co/wordpress/101334/security/firefox-chrome-browsers-flaws.html


0x04 ²Î¿¼Á´½Ó


https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html

https://nvd.nist.gov/vuln/detail/CVE-2020-6454

https://nvd.nist.gov/vuln/detail/CVE-2020-6423

https://nvd.nist.gov/vuln/detail/CVE-2020-6455


0x05 ¹¦·òÏß


2020-04-07 Chrome¹Ù·½°ä²¼·ì϶

2020-04-13 CVE°ä²¼¸Ã·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾