chromeÔÚÒ°ÀûÓÃ0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-07

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5786£¬£¬£¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬ £¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º 

Google Chrome < 72.0.3626.121


·ì϶¸ÅÊö


Google ChromeÊÇÒ»¿îWebä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£¡£FileReaderÊÇÆäÖеÄÒ»¸öÎļþ¶ÁÈ¡²å¼þ¡£¡£¡£¡£¡£¡£¡£¡£


¸Ã·ì϶ӰÏìËùÓвÙ×÷ϵͳÉϵÄChrome Èí¼þ£¬£¬£¬£¬£¬£¬ £¬£¬Ô̺¬Î¢Èí Windows¡¢Æ»¹û macOS ºÍ Linux ϵͳ¡£¡£¡£¡£¡£¡£¡£¡£


¸üÈÃÈ˲»°²µÄÊÇ£¬£¬£¬£¬£¬£¬ £¬£¬¹È¸èÖÒ¸æ³ÆÕâ¸ö0day RCE·ì϶ÒÑÔâÀûÓᣡ£¡£¡£¡£¡£¡£¡£


Google Chrome 72.0.3626.121֮ǰ°æ±¾£¬£¬£¬£¬£¬£¬ £¬£¬FileReaderµÄʵÏÖÖдæÔÚ¿ªÊͺó³ÁÓ÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£Õâ¸öʹÓúó¿ªÊÍ·ì϶ÊÇÒ»ÀàÄÚ´æ°Ü»µbug£¬£¬£¬£¬£¬£¬ £¬£¬ÔÊÐí°Ü»µ»òÅú¸ÄÄÚ´æÖеÄÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬£¬Ê¹µÃµÍȨÏÞÓû§¿ÉÄÜÔÚÊÜÓ°ÏìµÄϵͳ»òÈí¼þÉÏÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£Ëü¿Éµ¼ÖµÍȨÏÞ¹¥»÷Õß»ñÈ¡ Chrome web ä¯ÀÀÆ÷ÉϵÄȨÏÞ£¬£¬£¬£¬£¬£¬ £¬£¬ÌÓÒÝɳÏä±£»£»£»£» £»£»¤²¢ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£


ÒªÀûÓø÷ì϶£¬£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßËùÐèµÄÖ»ÊÇÓÕÆ­Êܺ¦Õß´ò¿ª¡¢»òÕß½«ËüÃdzÁ¶¨ÏòÖÁÒ»¸öÌØÊâ»ú¹ØµÄÍøÒ³£¬£¬£¬£¬£¬£¬ £¬£¬¶øÎÞÐèÈκνøÒ»²½µÄ½»»¥¡£¡£¡£¡£¡£¡£¡£¡£


¸Ã·ì϶ÓÉGoogle's Threat Analysis GroupµÄClement LecigneÓÚ2019-02-27»ã±¨£¬£¬£¬£¬£¬£¬ £¬£¬Ä¿Ç°Ã»Óа䲼ÆäËüϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£


±ÈÁ¦Á½¸ö°æ±¾µÄÔ´´úÂ룬£¬£¬£¬£¬£¬ £¬£¬·¢ÏÖthird_party/blink/renderer/core/fileapi/file_reader_loader.ccÓÐһЩŤת¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ·µ»Ø²¿ÃÅÁ˾Öʱ¸´ÔìArrayBufferÒÔÔ¤·À¶Ôͳһ¸öµ×²ãArrayBufferµÄ¶à¸öÒýÓᣡ£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



½¨¸´½¨Òé



ʹÓÃchromeä¯ÀÀÆ÷µÄÓû§Çë´ò¿ªchrome://settings/helpÒ³Ãæ²é¿´µ±Ç°ä¯ÀÀÆ÷°æ±¾£¬£¬£¬£¬£¬£¬ £¬£¬ÈôÊDz»ÊÇ×îаæ(72.0.3626.121)»á×Ô¶¯²é³­Éý¼¶£¬£¬£¬£¬£¬£¬ £¬£¬³ÁÆôÖ®ºó¼´¿É¸üе½×îаæ¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


²Î¿¼Á´½Ó


https://thehackernews.com/2019/03/update-google-chrome-hack.html

https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html

https://chromium.googlesource.com/chromium/src/+/150407e8d3610ff25a45c7c46877333c4425f062%5E%21/#F0