
Exploit proof-of-concept per CVE-2026-14382, una vulnerabilità ANGLE ad alta gravità in Chromium, con PoC a 32 bit e AArch64 che ottengono il controllo del contatore di programma tramite WebGL.
[$250000][492218546] High CVE-2026-14382: Insufficient validation of untrusted input in ANGLE. Reported by anonymous on 2026-03-13
La causa principale di questa vulnerabilità sembra essere simile a quella di CVE-2025-6558. Sulla base della mia analisi attuale, sospetto che possa essere una variante di CVE-2025-6558. Ho quindi adattato il PoC di CVE-2025-6558 e creato i seguenti file:
poc.c è il PoC principale, ma funziona solo in un ambiente a 32 bit. Come il PoC originale di CVE-2025-6558, consente il controllo del contatore di programma (PC).poc64.c dimostra che lo stesso problema può essere riprodotto anche in un ambiente AArch64. Tuttavia, il valore del PC risultante è imprevedibile e non può essere controllato in modo affidabile, rendendo lo sfruttamento difficile. Sto ancora indagando se sia possibile ottenere un controllo affidabile del PC.poc64.html è funzionalmente equivalente a poc64.c, ma il crash non viene attivato in modo affidabile a ogni tentativo. Se non si verifica il crash, prova a eseguirlo più volte.Pixel 7 Android16
--------- beginning of crash
06-29 11:17:38.359 26942 26942 F libc : Fatal signal 11 (SIGSEGV), code 1 (SEGV_MAPERR), fault addr 0x8d42a150 in tid 26942 (poc), pid 26942 (poc)
06-29 11:17:38.374 26950 26950 I crash_dump32: obtaining output fd from tombstoned, type: kDebuggerdTombstoneProto
06-29 11:17:38.375 747 747 I tombstoned: received crash request for pid 26942
06-29 11:17:38.375 26950 26950 I crash_dump32: performing dump of process 26942 (target tid = 26942)
06-29 11:17:38.393 1624 1624 W TracingMuxer: type=1400 audit(0.0:31735): avc: denied { write } for name="traced_producer" dev="tmpfs" ino=1316 scontext=u:r:gxp_logging:s0 tcontext=u:object_r:traced_producer_socket:s0 tclass=sock_file permissive=0
06-29 11:17:38.427 26950 26950 F DEBUG : *** *** *** *** *** *** *** *** *** *** *** *** *** *** *** ***
06-29 11:17:38.427 26950 26950 F DEBUG : Build fingerprint: 'google/panther/panther:16/BP2A.250605.031.A2/13578606:user/release-keys'
06-29 11:17:38.427 26950 26950 F DEBUG : Revision: 'MP1.0'
06-29 11:17:38.427 26950 26950 F DEBUG : ABI: 'arm'
06-29 11:17:38.427 26950 26950 F DEBUG : Timestamp: 2025-06-29 11:17:38.376836685+0800
06-29 11:17:38.427 26950 26950 F DEBUG : Process uptime: 1s
06-29 11:17:38.427 26950 26950 F DEBUG : Cmdline: ./poc
06-29 11:17:38.427 26950 26950 F DEBUG : pid: 26942, tid: 26942, name: poc >>> ./poc <<<
06-29 11:17:38.427 26950 26950 F DEBUG : uid: 2000
06-29 11:17:38.427 26950 26950 F DEBUG : signal 11 (SIGSEGV), code 1 (SEGV_MAPERR), fault addr 0x8d42a150
06-29 11:17:38.427 26950 26950 F DEBUG : r0 f3dc1630 r1 00000000 r2 00000000 r3 8d42a150
06-29 11:17:38.427 26950 26950 F DEBUG : r4 f319fc7c r5 f76bb2d0 r6 00000000 r7 f76bb2dc
06-29 11:17:38.427 26950 26950 F DEBUG : r8 f319fbd8 r9 00000000 r10 f3194290 r11 00000001
06-29 11:17:38.427 26950 26950 F DEBUG : ip 00000000 sp fff04368 lr f47b35af pc 8d42a150
06-29 11:17:38.427 26950 26950 F DEBUG : 5 total frames
06-29 11:17:38.427 26950 26950 F DEBUG : backtrace:
06-29 11:17:38.427 26950 26950 F DEBUG : NOTE: Function names and BuildId information is missing for some frames due
06-29 11:17:38.427 26950 26950 F DEBUG : NOTE: to unreadable libraries. For unwinds of apps, only shared libraries
06-29 11:17:38.427 26950 26950 F DEBUG : NOTE: found under the lib/ directory are readable.
06-29 11:17:38.427 26950 26950 F DEBUG : NOTE: On this device, run setenforce 0 to make the libraries readable.
06-29 11:17:38.427 26950 26950 F DEBUG : NOTE: Unreadable libraries:
06-29 11:17:38.427 26950 26950 F DEBUG : NOTE: /data/local/tmp/poc
06-29 11:17:38.427 26950 26950 F DEBUG : #00 pc 8d42a150 <unknown>
06-29 11:17:38.427 26950 26950 F DEBUG : #01 pc 006185ad /vendor/lib/egl/libGLES_mali.so (gles_drawp_handle_dependencies(gles_context*, gles_draw_call*, glescore_submission*)+196) (BuildId: da7af0632b11c153bc5a10aa30fdc8a1314007c5)
06-29 11:17:38.427 26950 26950 F DEBUG : #02 pc 00619a6b /vendor/lib/egl/libGLES_mali.so (gles_drawp_draw_common+794) (BuildId: da7af0632b11c153bc5a10aa30fdc8a1314007c5)
06-29 11:17:38.427 26950 26950 F DEBUG : #03 pc 005d1373 /vendor/lib/egl/libGLES_mali.so (gles_draw_draw_arrays+32) (BuildId: da7af0632b11c153bc5a10aa30fdc8a1314007c5)
06-29 11:17:38.427 26950 26950 F DEBUG : #04 pc 000022fc /data/local/tmp/poc
--------- beginning of system
arm32:
$NDK/toolchains/llvm/prebuilt/linux-x86_64/bin/clang poc.c -lGLESv3 -lGLESv2 -lEGL -lm --target=armv7a-linux-android34 -g -O0 -o poc
aarch64:
$NDK/toolchains/llvm/prebuilt/linux-x86_64/bin/clang poc.c -lGLESv3 -lGLESv2 -lEGL -lm --target=aarch64-linux-android34 -g -O0 -o poc
commit 65db666ac2cf205fcc36db8bb5b9cd87f94808ac (HEAD -> 148.0.7778.167, tag: 148.0.7778.167)
Author: Juan Mojica <[email protected]>
Date: Mon May 11 16:14:03 2026 -0700
[148] [lens] Delay searchbox initialization to fix flaky thumbnail
Original change's description:
> [lens] Delay searchbox initialization to fix flaky thumbnail
>
> Move the OnPageBound() invocation from the LensSearchboxHandler
> constructor to the LensSearchboxController registration methods.
>
> Previously, OnPageBound() fired during the handler object's
> construction. At this stage, the controller's pointer to the handler was
> still null, causing initial state flushes, such as cached thumbnails and
> pending text queries, to be skipped.
>
> Delaying this notification until the handler is fully stored in the
> controller ensures that the initial state push always succeeds. This
> resolves the flaky viewport thumbnail issue by securing the existing
> state propagation order without introducing side effects.
>
> Demo: http://shortn/_DGK0HD8ARP
> Bug: b:510419641
> Change-Id: If0abf11b601f78f5555969295e224cec30a82162
> Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7830897
> Auto-Submit: Juan Mojica <[email protected]>
> Commit-Queue: Juan Mojica <[email protected]>
> Reviewed-by: Riley Tatum <[email protected]>
> Commit-Queue: Riley Tatum <[email protected]>
> Reviewed-by: Duncan Mercer <[email protected]>
> Cr-Commit-Position: refs/heads/main@{#1627226}
# Set build arguments here. See `gn help buildargs`.
is_official_build = true
is_debug = false
symbol_level = 2
v8_symbol_level = 2
blink_symbol_level = 2
is_component_build = false
proprietary_codecs = true
ffmpeg_branding = "Chrome"
dcheck_always_on =false
optimize_webui = true
android_static_analysis = "off"
target_os = "android"
target_cpu = "arm64"
treat_warnings_as_errors = false
poc64.html