<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Chrome on iamelli0t's blog</title><link>https://iamelli0t.github.io/tags/chrome/</link><description>Recent content in Chrome on iamelli0t's blog</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 20 Apr 2021 00:00:00 +0000</lastBuildDate><atom:link href="https://iamelli0t.github.io/tags/chrome/index.xml" rel="self" type="application/rss+xml"/><item><title>Analysis of Chromium issue 1196683, 1195777</title><link>https://iamelli0t.github.io/2021/04/20/Chromium-Issue-1196683-1195777/</link><pubDate>Tue, 20 Apr 2021 00:00:00 +0000</pubDate><guid>https://iamelli0t.github.io/2021/04/20/Chromium-Issue-1196683-1195777/</guid><description>&lt;p&gt;On April 12, a code commit[1] in Chromium get people&amp;rsquo;s attention. This is a bugfix for some vulnerability in Chromium Javascript engine v8. At the same time, the regression test case regress-1196683.js for this bugfix was also submitted. Based on this regression test case, some security researcher published an exploit sample[2]. Due to Chrome release pipeline, the vulnerability wasn&amp;rsquo;t been fixed in Chrome stable update until April 13[3]. &lt;br&gt;&lt;/p&gt;
&lt;p&gt;Coincidentally, on April 15, another code commit[4] of some bugfix in v8 has also included one regression test case regress-1195777.js. Based on this test case, the exploit sample was exposed again[5]. Since the latest Chrome stable version does not pull this bugfix commit, the sample can still exploit in render process of latest Chrome. When the vulnerable Chormium browser accesses a malicious link without enabling the sandbox (&amp;ndash;no-sandbox), the vulnerability will be triggered and caused remote code execution.&lt;br&gt;&lt;/p&gt;</description></item></channel></rss>