
Proof-of-Concept-Exploit für CVE-2026-3909, eine Out-of-Bounds-Schwachstelle in Chromium Skia, mit Patches und Absturzanalyse für zuverlässige Auslösung in realen Browser-Umgebungen.
Dieses Repository enthält einen Proof-of-Concept (PoC) für CVE-2026-3909, der im Chromium-Browser zuverlässig ausgelöst werden kann.
Der offizielle Skia-Fix für diese Schwachstelle enthielt nur einen vereinfachten Demonstrationstestfall:
Dieser kann nicht in einer echten Chromium-Umgebung ausgeführt werden. Die offizielle Demo war absichtlich eingeschränkt und ließ wichtige Auslösebedingungen aus.
Dieser PoC basiert auf der offiziellen Demo und wurde modifiziert, um die Schwachstelle zuverlässig in einer echten Chromium-Browser-Umgebung auszulösen.
Dieser PoC besteht aus Änderungen an den folgenden Dateien:
raster_implementation.cc.patchPfad: /src/gpu/command_buffer/client/raster_implementation.cc
SkChromeRemoteGlyphCache.cpp.patchPfad: /src/third_party/skia/src/text/gpu/SkChromeRemoteGlyphCache.cpp
Zusätzlich zu den beiden vorhandenen Patch-Dateien können Sie Debugging-Code innerhalb der Funktion DrawAtlas::hasID() hinzufügen. Dies ermöglicht es Ihnen, zu analysieren und zu beobachten, warum der Abbruch ausgelöst wird.``` bool hasID(const skgpu::PlotLocator& plotLocator) { if (!plotLocator.isValid()) { return false; }
uint32_t plot = plotLocator.plotIndex();
uint32_t page = plotLocator.pageIndex();
// patch code
printf("[*] POC plot idx: %x fNumPlots: %x\n", plot, fNumPlots);
// origin code
uint64_t plotGeneration = fPages[page].fPlotArray[plot]->genID();
uint64_t locatorGeneration = plotLocator.genID();
return plot < fNumPlots && page < fNumActivePages && plotGeneration == locatorGeneration;
}
```bash
# Install dependencies
npm install
# Run the development server
npm run dev
Open your browser and navigate to http://localhost:3000.
The tool also provides a CLI for automation:
# Run a basic port scan
secscan scan --target 192.168.1.0/24 --ports 1-1000
# Run a vulnerability scan
secscan vuln --target example.com --profile full
# Export results to JSON
secscan export --format json --output results.json
Configuration is managed through a YAML file located at config/settings.yaml:
server:
host: 0.0.0.0
port: 3000
scanning:
default_timeout: 30
max_threads: 100
rate_limit: 50
notifications:
email:
enabled: false
smtp_server: smtp.example.com
from_address: [email protected]
The REST API provides programmatic access to all functionality:
| Endpoint | Method | Description |
|---|---|---|
/api/v1/projects | GET | List all projects |
/api/v1/projects | POST | Create a new project |
/api/v1/scans | POST | Start a new scan |
/api/v1/scans/:id | GET | Get scan status |
/api/v1/results/:id | GET | Retrieve scan results |
API requests require a Bearer token:
curl -H "Authorization: Bearer $API_TOKEN" \
https://api.example.com/api/v1/projects
We welcome contributions! Please see CONTRIBUTING.md for guidelines.
This project is licensed under the MIT License - see the LICENSE file for details.``` [*] POC plot idx: 1f fNumPlots: 10
## Git log
Chromium:```
commit e00a64ead1abef9447943efede7bc26362ac3797 (HEAD -> 146.0.7680.71, tag: 146.0.7680.71)
Author: Roger McFarlane <[email protected]>
Date: Mon Mar 9 12:52:01 2026 -0700
[M146-desktop-respin] Make LimitedLayerEntropyCostTracker time-aware.
This change modifies the LimitedLayerEntropyCostTracker to account for
the entropy cost of studies that are active at a specific evaluation
time. The evaluation time is passed to the tracker's constructor and is
used to check against the study's filter dates and Google web visibility
dates.
The current time for entropy evaluation is sourced from
VariationsIdsProvider.
(cherry picked from commit 2ec2c50b47686def251947a2675a207863803cac)
Bug: 490248046, 490432663
Change-Id: I3174730f35b037d533bf10b2b1d0531e3781acfe
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7639358
Reviewed-by: Alexei Svitkine <[email protected]>
Commit-Queue: Alexei Svitkine <[email protected]>
Cr-Original-Commit-Position: refs/heads/main@{#1595543}
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7637760
Bot-Commit: Rubber Stamper <[email protected]>
Cr-Commit-Position: refs/branch-heads/7680_65@{#23}
Cr-Branched-From: efe36a9d42443b4091a5be1be21e93ceff9b7a5e-refs/branch-heads/7680@{#1898}
Cr-Branched-From: 76b7d80e5cda23fe6537eed26d68c92e995c7f39-refs/heads/main@{#1582197}
gn help buildargs.is_official_build = false
is_debug = true
symbol_level = 2
v8_symbol_level = 2
blink_symbol_level = 2
is_component_build = false
proprietary_codecs = true
ffmpeg_branding = "Chrome"
v8_enable_sandbox = true
dcheck_always_on = true
optimize_webui = true
target_os = "linux"
target_cpu = "x64"
## Verwendung
1. Wenden Sie die beiden Patch-Dateien auf eine verwundbare Version von Chromium an.
2. Öffnen Sie den Browser `chrome <pfad>/trigger.html`
## Abbruch```
gen/third_party/libc++/src/include/__memory/unique_ptr.h:578: libc++ Hardening assertion __checker_.__in_bounds<deleter_type>(std::__to_address(__ptr_), __i) failed: unique_ptr<T[]>::operator[](https://github.com/jaf0rk/cve-2026-3909/blob/main/index): index out of range
Received signal 6