¡¾·ì϶¹«¸æ¡¿Google Chrome ýÌåÁ÷¿ªÊͺóÖØÓ÷ì϶(CVE-2025-8292)
°ä²¼¹¦·ò 2025-07-31Ò»¡¢¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | Google Chrome ýÌåÁ÷¿ªÊͺóÖØÓ÷ì϶ | ||
CVE ID | CVE-2025-8292 | ||
·ì϶ÀàÐÍ | ¿ªÊͺóÖØÓà | ·¢ÏÖ¹¦·ò | 2025-07-31 |
·ì϶ÆÀ·Ö | 8.8 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Google Chrome ÊÇÓɹȸ迪·¢µÄ¿çÆ½Ì¨ÍøÒ³ä¯ÀÀÆ÷£¬£¬ÒÔÆäËÙ¶È¡¢¡¢°²È«ÐԺͼò½àµÄ½çÃæ¶øÎÅÃû¡£¡£¡£¡£Ëü»ùÓÚ¿ªÔ´µÄChromiumÏîÄ¿£¬£¬Ö§³ÖÏÖ´úÍøÒ³³ß¶È£¬£¬ÓµÓÐ׳´óµÄÀ©´óÐÔ¡£¡£¡£¡£ChromeµÄɳÏä¼¼ÊõÄܹ»ÏÞ¶ÈÍøÒ³ÖеĶñÒâ´úÂ룬£¬¼ÓÇ¿ä¯ÀÀÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£Ëü»¹ÌṩÁËͬ²½Ö°ÄÜ£¬£¬ÔÊÐíÓû§ÔÚ¶à¸öÉ豸¼äͬ²½ÊéÇ©¡¢¡¢º¹Çà¼Í¼µÈÊý¾Ý¡£¡£¡£¡£´ËÍ⣬£¬Chrome¶¨ÆÚ¸üУ¬£¬ÐÞ¸´ÒÑÖª·ì϶²¢¼ÓǿְÄÜ£¬£¬ÊÇÈ«ÇòʹÓÃ×î¿í·ºµÄä¯ÀÀÆ÷Ö®Ò»¡£¡£¡£¡£
2025Äê7ÔÂ31ÈÕ£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Chromeä¯ÀÀÆ÷´æÔÚÒ»¸ö¸ßΣ·ì϶£¨CVE-2025-8292£©£¬£¬Ô´ÓÚMedia Stream×é¼þÖеÄuse-after-freeÄڴ濪ÊͺóʹÓÃÃýÎ󡣡£¡£¡£¹¥»÷Õß¿Éͨ¹ý»ú¹ØÌض¨Ã½ÌåÁ÷²Ù×÷ÓÕ·¢¿ªÊͺó½Ó¼û£¬£¬Ôì³ÉÄÚ´æ·ÛË飬£¬½ø¶ø¿ÉÄÜʵÏÖä¯ÀÀÆ÷±ÀÀ£»£»òÔ¶³Ì´úÂëÖ´ÐУ¬£¬·ì϶ÆÀ·Ö8.8·Ö£¬£¬·ì϶¼¶±ð¸ßΣ¡£¡£¡£¡£
¶þ¡¢¡¢Ó°ÏìÁìÓò
Èý¡¢¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º£ºhttps://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_29.html
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ