
CVE-2026-3909에 대한 개념 증명 익스플로잇으로, Chromium Skia의 경계를 벗어난(out-of-bounds) 취약점이며, 실제 브라우저 환경에서 안정적으로 트리거하기 위한 패치와 크래시 분석을 포함합니다.
이 저장소는 CVE-2026-3909에 대한 개념 증명(PoC)으로, Chromium 브라우저에서 안정적으로 트리거할 수 있습니다.
이 취약점에 대한 공식 Skia 수정본은 단순화된 데모 테스트 케이스만 포함하고 있습니다:
이는 실제 Chromium 환경에서 실행할 수 없습니다. 공식 데모는 의도적으로 제한되었으며 핵심 트리거 조건이 누락되었습니다.
이 PoC는 공식 데모를 기반으로 구축되었으며, 실제 Chromium 브라우저 환경 내에서 취약점을 안정적으로 트리거하도록 수정되었습니다.
이 PoC는 다음 파일에 대한 수정 사항으로 구성됩니다:
raster_implementation.cc.patch경로: <Chromium 루트 디렉터리>/src/gpu/command_buffer/client/raster_implementation.cc
SkChromeRemoteGlyphCache.cpp.patch경로: <Chromium 루트 디렉터리>/src/third_party/skia/src/text/gpu/SkChromeRemoteGlyphCache.cpp
기존 두 개의 패치 파일 외에도 DrawAtlas::hasID() 함수 내부에 디버깅 코드를 추가할 수 있습니다. 이를 통해 abort가 트리거되는 이유를 분석하고 관찰할 수 있습니다.``` bool hasID(const skgpu::PlotLocator& plotLocator) { if (!plotLocator.isValid()) { return false; }
uint32_t plot = plotLocator.plotIndex();
uint32_t page = plotLocator.pageIndex();
// patch code
printf("[*] POC plot idx: %x fNumPlots: %x\n", plot, fNumPlots);
// origin code
uint64_t plotGeneration = fPages[page].fPlotArray[plot]->genID();
uint64_t locatorGeneration = plotLocator.genID();
return plot < fNumPlots && page < fNumActivePages && plotGeneration == locatorGeneration;
}
출력:```
[*] POC plot idx: 1f fNumPlots: 10
Chromium:``` commit e00a64ead1abef9447943efede7bc26362ac3797 (HEAD -> 146.0.7680.71, tag: 146.0.7680.71) Author: Roger McFarlane [email protected] Date: Mon Mar 9 12:52:01 2026 -0700
[M146-desktop-respin] Make LimitedLayerEntropyCostTracker time-aware.
This change modifies the LimitedLayerEntropyCostTracker to account for
the entropy cost of studies that are active at a specific evaluation
time. The evaluation time is passed to the tracker's constructor and is
used to check against the study's filter dates and Google web visibility
dates.
The current time for entropy evaluation is sourced from
VariationsIdsProvider.
(cherry picked from commit 2ec2c50b47686def251947a2675a207863803cac)
Bug: 490248046, 490432663
Change-Id: I3174730f35b037d533bf10b2b1d0531e3781acfe
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7639358
Reviewed-by: Alexei Svitkine <[email protected]>
Commit-Queue: Alexei Svitkine <[email protected]>
Cr-Original-Commit-Position: refs/heads/main@{#1595543}
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7637760
Bot-Commit: Rubber Stamper <[email protected]>
Cr-Commit-Position: refs/branch-heads/7680_65@{#23}
Cr-Branched-From: efe36a9d42443b4091a5be1be21e93ceff9b7a5e-refs/branch-heads/7680@{#1898}
Cr-Branched-From: 76b7d80e5cda23fe6537eed26d68c92e995c7f39-refs/heads/main@{#1582197}
## Build args```
# Set build arguments here. See `gn help buildargs`.
is_official_build = false
is_debug = true
symbol_level = 2
v8_symbol_level = 2
blink_symbol_level = 2
is_component_build = false
proprietary_codecs = true
ffmpeg_branding = "Chrome"
v8_enable_sandbox = true
dcheck_always_on = true
optimize_webui = true
target_os = "linux"
target_cpu = "x64"
chrome <path>/trigger.htmlgen/third_party/libc++/src/include/__memory/unique_ptr.h:578: libc++ Hardening assertion _checker.__in_bounds<deleter_type>(std::__to_address(_ptr), __i) failed: unique_ptr<T[]>::operator: index out of range Received signal 6