Chrome |¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-150x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
Chrome |
CVE-2020-6454 |
ÄÚ´æ·ÛËé |
¸ßΣ |
ÊÇ |
Chrome < 81.0.4044.92 |
|
Chrome |
CVE-2020-6423 |
ÄÚ´æ·ÛËé |
¸ßΣ |
ÊÇ |
Chrome < 81.0.4044.92 |
|
Chrome |
CVE-2020-6455 |
»º³åÇøÒç³ö |
¸ßΣ |
ÊÇ |
Chrome < 81.0.4044.92 |
0x01 ·ì϶ÏêÇé
Google ChromeÊÇÃÀ¹ú¹È¸è£¨Google£©¹«Ë¾µÄÒ»¿îWebä¯ÀÀÆ÷¡£
2020Äê4ÔÂ7ÈÕ£¬Google°ä²¼ÁËChrome 81°æ±¾£¬ÆäÖÐÔ̺¬32¸ö°²È«·ì϶£¬ÓÐ3¸ö±»ÆÀΪ¸ßΣ£¬¾ßÌåÈçÏ£º
CVE-2020-6454ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖдæÔÚUAF·ì϶¡£Ô¶³Ì¹¥»÷Õß¿ÉÓÕʹÓû§×°ÖöñÒâÀ©´óÀ´ÀûÓô˷ì϶£¬½øÒ»²½Ö´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£
CVE-2020-6423 ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖеÄaudio´æÔÚUAF·ì϶¡£audioÊÇÆäÖеÄÒ»¸öÒôƵ×é¼þ¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¾«ÐÄÔì×÷µÄHTMLÒ³ÃæÀ´ÀûÓô˷ì϶£¬½øÒ»²½Ö´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£
CVE-2020-6855 ÊÇGoogle Chrome 81.0.4044.92֮ǰ°æ±¾ÖеÄWebSQL´æÔÚ»º³åÇøÃýÎó·ì϶¡£WebSQLÊÇÆäÖеÄÒ»¸öÓÃÓÚ½«Êý¾Ý´æ´¢ÔÚÊý¾Ý¿âÖеÄÍøÒ³API£¨ÀûÓ÷¨Ê½±à³Ì½Ó¿Ú£©¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý¾«ÐÄÔì×÷µÄHTMLÒ³ÃæÀ´ÀûÓô˷ì϶£¬½øÒ»²½Ö´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£
0x02 ´ëÖý¨Òé
³§ÉÌÒѰ䲼Éý¼¶²¹¶¡£¬ÏÂÔØÁ´½Ó£º
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
0x03 ÓйØÐÂÎÅ
https://securityaffairs.co/wordpress/101334/security/firefox-chrome-browsers-flaws.html
0x04 ²Î¿¼Á´½Ó
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html
https://nvd.nist.gov/vuln/detail/CVE-2020-6454
https://nvd.nist.gov/vuln/detail/CVE-2020-6423
https://nvd.nist.gov/vuln/detail/CVE-2020-6455
0x05 ¹¦·òÏß
2020-04-07 Chrome¹Ù·½°ä²¼·ì϶
2020-04-13 CVE°ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ