¡¾¸´ÏÖ¡¿Google Chromeä¯ÀÀÆ÷ÔÚÒ°ÀûÓ÷ì϶£¨CVE-2025-6554£©

°ä²¼¹¦·ò 2025-07-03

6ÔÂ30ÈÕ £¬Google °²È«°ä²¼ÁËÒ»¸öGoogle Chromeä¯ÀÀÆ÷µÄ¸ßΣ·ì϶£¨CVE-2025-6554£© £¬²¢°µÊ¾¸Ã·ì϶´æÔÚÔÚÒ°·ì϶ÀûÓà £¬Í¨¹ý½Ó¼û¶ñÒâ»ú¹ØµÄÍøÒ³µ¼ÖÂÔ¶³ÌËÁÒâ´úÂëÖ´ÐС£¡£¡£ÎªÔ¤·À¸Ã·ì϶´øÀ´µÄ°²È«·çÏÕ £¬½¨ÒéGoogle ChromeÓû§ÊµÊ±¸üÐÂä¯ÀÀÆ÷°æ±¾¡£¡£¡£


Ó°Ïì°æ±¾


< 138.0.7204.96/.97 (Windows)

< 138.0.7204.92/.93 (Mac)

< 138.0.7204.92 (Linux)


·ì϶³ÉÒò


¸Ã·ì϶´æÔÚÓÚGoogle Chromeä¯ÀÀÆ÷µÄ¾ç±¾½âÎöÒýÇæV8ÖС£¡£¡£¶ÔÓÚlet½ç˵µÄ±äÁ¿foo £¬ÔÚδÔËÐе½Æä½ç˵µÄ´úÂëÐÐʱ £¬ÆäλÓÚTemperal dead zone(tdz) £¬¶ÔÆä½Ó¼û»áÅ׳öReferenceError¡£¡£¡£


ͼƬ1.png


IgnitionÔÚ½âÎö¡°Optional chaining¡±²Ù×÷ʱ £¬Î´²ÎÓë¶Ôtdz°ó¶¨±äÁ¿µÄ½Ó¼û²é³­ £¬µ¼ÖÂholeֵй©¡£¡£¡£


ͼƬ2.png


·ì϶¸´ÏÖ


ͼƬ3.png


ÐÞ¸´½¨Òé


Google Chrome¹Ù·½ÒѾ­°ä²¼Á˸üа汾¡£¡£¡£×°ÖÃGoogle Chromeä¯ÀÀÆ÷ÒªÔÚÆä¹Ù·½ÍøÕ¾¸ßµÍÔØ×îÐÂ×°Öðü £¬ÒÑ×°ÖÃÓû§ÐèÔÚ±¾µØÖØÐµÇ¼ÀûÓÃÒÔʵÏÖ¸üС£¡£¡£


²Î¿¼Á´½Ó£º£º£º

[1]https://chromereleases.googleblog.com/

[2]https://chromium-review.googlesource.com/c/v8/v8/+/6678591/3/src/interpreter/bytecode-generator.cc#b1233


OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Äê £¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò» £¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£¡£¡£½ØÖÁĿǰ £¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶6500Óà¸ö £¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑС¢Êý¾Ý°²È«×êÑС¢5G°²È«×êÑС¢AI+°²È«×êÑС¢ÎÀÐǰ²È«×êÑС¢ÔËÓªÉÌ»ù´¡ÉèÊ©°²È«×êÑС¢Òƶ¯°²È«×êÑС¢ÎïÁªÍø°²È«×êÑС¢³µÁªÍø°²È«×êÑС¢¹¤¿Ø°²È«×êÑС¢ÐÅ´´°²È«×êÑС¢Ôư²È«×êÑС¢ÎÞÏß°²È«×êÑС¢¸ß¼¶Íþв×êÑС¢¹¥·ÀÆ¥µÐ¼¼Êõ×êÑС£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£


adlab.jpg