
Google Chrome の Use After Free 脆弱性が報告されました
バグ報奨金総額: $6.000
これは以下の概念実証(Proof of Concept)です:
[Google Security_Severity] CVE。
[HIGH] CVE-2021-30573 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30573
Google ブログ記事:
https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop_20.html
要件:特にありません。古いバージョンの Google Chrome [91.0.4472.77] + [stable] (Official Build) (64-bit) で HTML ファイルを実行するだけです。
poc-exploit.html (The bug works in Google Chrome 91 or lower. It is patched in 92+)
前述のバグは「Security For Everyone Team」によって報告されたものです。