Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
CVE-2026-14382 — PoC-эксплойт для CVE-2026-14382 — уязвимости ANGLE высокой степени опасности в Chromium, с PoC для 32-битных систем и AArch64, обеспечивающий контроль над счётчиком команд через WebGL. | Kitploit
Инструменты/GitHubGitHub/jaf0rk/cve-2026-14382
Безопасность AndroidКриминалистика памятиАнализ уязвимостейЭксплуатацияЭксплуатация веб-приложенийВеб-безопасностьЭксплуатация Бинарных Файлов
GitHubjaf0rk/cve-2026-14382

CVE-2026-14382

PoC-эксплойт для CVE-2026-14382 — уязвимости ANGLE высокой степени опасности в Chromium, с PoC для 32-битных систем и AArch64, обеспечивающий контроль над счётчиком команд через WebGL.

Репозиторий
71122 месяцев назадЕщё не проверено

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться

CVE-2026-14382

Триггер бинарного файла

Исправление ошибки

[$250000][492218546] High CVE-2026-14382: Insufficient validation of untrusted input in ANGLE. Reported by anonymous on 2026-03-13

Коренная причина этой уязвимости, по-видимому, аналогична CVE-2025-6558. Исходя из моего текущего анализа, я подозреваю, что это может быть вариант CVE-2025-6558. Поэтому я адаптировал PoC для CVE-2025-6558 и создал следующие файлы:

  • poc.c является основным PoC, но работает только в 32-битной среде. Как и в оригинальном PoC для CVE-2025-6558, он позволяет управлять программным счётчиком (PC).
  • poc64.c демонстрирует, что та же проблема может быть воспроизведена и в среде AArch64. Однако результирующее значение PC непредсказуемо и не может быть надёжно контролируемо, что затрудняет эксплуатацию. Я всё ещё исследую, можно ли добиться надёжного контроля PC.
  • poc64.html функционально эквивалентен poc64.c, но сбой происходит не надёжно при каждой попытке. Если сбой не происходит, попробуйте запустить его несколько раз.

Устройство

Pixel 7 Android16

Сбой

--------- beginning of crash
06-29 11:17:38.359 26942 26942 F libc    : Fatal signal 11 (SIGSEGV), code 1 (SEGV_MAPERR), fault addr 0x8d42a150 in tid 26942 (poc), pid 26942 (poc)
06-29 11:17:38.374 26950 26950 I crash_dump32: obtaining output fd from tombstoned, type: kDebuggerdTombstoneProto
06-29 11:17:38.375   747   747 I tombstoned: received crash request for pid 26942
06-29 11:17:38.375 26950 26950 I crash_dump32: performing dump of process 26942 (target tid = 26942)
06-29 11:17:38.393  1624  1624 W TracingMuxer: type=1400 audit(0.0:31735): avc:  denied  { write }  for  name="traced_producer" dev="tmpfs" ino=1316 scontext=u:r:gxp_logging:s0 tcontext=u:object_r:traced_producer_socket:s0 tclass=sock_file permissive=0
06-29 11:17:38.427 26950 26950 F DEBUG   : *** *** *** *** *** *** *** *** *** *** *** *** *** *** *** ***
06-29 11:17:38.427 26950 26950 F DEBUG   : Build fingerprint: 'google/panther/panther:16/BP2A.250605.031.A2/13578606:user/release-keys'
06-29 11:17:38.427 26950 26950 F DEBUG   : Revision: 'MP1.0'
06-29 11:17:38.427 26950 26950 F DEBUG   : ABI: 'arm'
06-29 11:17:38.427 26950 26950 F DEBUG   : Timestamp: 2025-06-29 11:17:38.376836685+0800
06-29 11:17:38.427 26950 26950 F DEBUG   : Process uptime: 1s
06-29 11:17:38.427 26950 26950 F DEBUG   : Cmdline: ./poc
06-29 11:17:38.427 26950 26950 F DEBUG   : pid: 26942, tid: 26942, name: poc  >>> ./poc <<<
06-29 11:17:38.427 26950 26950 F DEBUG   : uid: 2000
06-29 11:17:38.427 26950 26950 F DEBUG   : signal 11 (SIGSEGV), code 1 (SEGV_MAPERR), fault addr 0x8d42a150
06-29 11:17:38.427 26950 26950 F DEBUG   :     r0  f3dc1630  r1  00000000  r2  00000000  r3  8d42a150
06-29 11:17:38.427 26950 26950 F DEBUG   :     r4  f319fc7c  r5  f76bb2d0  r6  00000000  r7  f76bb2dc
06-29 11:17:38.427 26950 26950 F DEBUG   :     r8  f319fbd8  r9  00000000  r10 f3194290  r11 00000001
06-29 11:17:38.427 26950 26950 F DEBUG   :     ip  00000000  sp  fff04368  lr  f47b35af  pc  8d42a150
06-29 11:17:38.427 26950 26950 F DEBUG   : 5 total frames
06-29 11:17:38.427 26950 26950 F DEBUG   : backtrace:
06-29 11:17:38.427 26950 26950 F DEBUG   :   NOTE: Function names and BuildId information is missing for some frames due
06-29 11:17:38.427 26950 26950 F DEBUG   :   NOTE: to unreadable libraries. For unwinds of apps, only shared libraries
06-29 11:17:38.427 26950 26950 F DEBUG   :   NOTE: found under the lib/ directory are readable.
06-29 11:17:38.427 26950 26950 F DEBUG   :   NOTE: On this device, run setenforce 0 to make the libraries readable.
06-29 11:17:38.427 26950 26950 F DEBUG   :   NOTE: Unreadable libraries:
06-29 11:17:38.427 26950 26950 F DEBUG   :   NOTE:   /data/local/tmp/poc
06-29 11:17:38.427 26950 26950 F DEBUG   :       #00 pc 8d42a150  <unknown>
06-29 11:17:38.427 26950 26950 F DEBUG   :       #01 pc 006185ad  /vendor/lib/egl/libGLES_mali.so (gles_drawp_handle_dependencies(gles_context*, gles_draw_call*, glescore_submission*)+196) (BuildId: da7af0632b11c153bc5a10aa30fdc8a1314007c5)
06-29 11:17:38.427 26950 26950 F DEBUG   :       #02 pc 00619a6b  /vendor/lib/egl/libGLES_mali.so (gles_drawp_draw_common+794) (BuildId: da7af0632b11c153bc5a10aa30fdc8a1314007c5)
06-29 11:17:38.427 26950 26950 F DEBUG   :       #03 pc 005d1373  /vendor/lib/egl/libGLES_mali.so (gles_draw_draw_arrays+32) (BuildId: da7af0632b11c153bc5a10aa30fdc8a1314007c5)
06-29 11:17:38.427 26950 26950 F DEBUG   :       #04 pc 000022fc  /data/local/tmp/poc
--------- beginning of system

Сборка

arm32:

$NDK/toolchains/llvm/prebuilt/linux-x86_64/bin/clang poc.c -lGLESv3 -lGLESv2 -lEGL -lm --target=armv7a-linux-android34 -g -O0 -o poc

aarch64:

$NDK/toolchains/llvm/prebuilt/linux-x86_64/bin/clang poc.c -lGLESv3 -lGLESv2 -lEGL -lm --target=aarch64-linux-android34 -g -O0 -o poc

Триггер Chrome

Версия

commit 65db666ac2cf205fcc36db8bb5b9cd87f94808ac (HEAD -> 148.0.7778.167, tag: 148.0.7778.167)
Author: Juan Mojica <[email protected]>
Date:   Mon May 11 16:14:03 2026 -0700

    [148] [lens] Delay searchbox initialization to fix flaky thumbnail
    
    Original change's description:
    > [lens] Delay searchbox initialization to fix flaky thumbnail
    >
    > Move the OnPageBound() invocation from the LensSearchboxHandler
    > constructor to the LensSearchboxController registration methods.
    >
    > Previously, OnPageBound() fired during the handler object's
    > construction. At this stage, the controller's pointer to the handler was
    > still null, causing initial state flushes, such as cached thumbnails and
    > pending text queries, to be skipped.
    >
    > Delaying this notification until the handler is fully stored in the
    > controller ensures that the initial state push always succeeds. This
    > resolves the flaky viewport thumbnail issue by securing the existing
    > state propagation order without introducing side effects.
    >
    > Demo: http://shortn/_DGK0HD8ARP
    > Bug: b:510419641
    > Change-Id: If0abf11b601f78f5555969295e224cec30a82162
    > Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7830897
    > Auto-Submit: Juan Mojica <[email protected]>
    > Commit-Queue: Juan Mojica <[email protected]>
    > Reviewed-by: Riley Tatum <[email protected]>
    > Commit-Queue: Riley Tatum <[email protected]>
    > Reviewed-by: Duncan Mercer <[email protected]>
    > Cr-Commit-Position: refs/heads/main@{#1627226}
    

Аргументы сборки

# Set build arguments here. See `gn help buildargs`.
is_official_build = true
is_debug = false
symbol_level = 2
v8_symbol_level = 2
blink_symbol_level = 2
is_component_build = false  
proprietary_codecs = true   
ffmpeg_branding = "Chrome"  
dcheck_always_on =false
optimize_webui = true
android_static_analysis = "off"
target_os = "android"
target_cpu = "arm64"

treat_warnings_as_errors = false

Воспроизведение

  1. Примените patch webgl_rendering_context_base.cc.patch
  2. Соберите Chromium
  3. Откройте po64.html
Скачать инструмент