Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-3909 — CVE-2026-3909 的概念验证漏洞利用程序,针对 Chromium Skia 越界漏洞,包含补丁和崩溃分析,可在真实浏览器环境中实现可靠触发。 | Kitploit
工具/GitHubGitHub/jaf0rk/cve-2026-3909
漏洞分析漏洞利用Web应用程序漏洞利用模糊测试二进制分析
GitHubjaf0rk/cve-2026-3909

CVE-2026-3909

CVE-2026-3909 的概念验证漏洞利用程序,针对 Chromium Skia 越界漏洞,包含补丁和崩溃分析,可在真实浏览器环境中实现可靠触发。

查看仓库
2175个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2026-3909 Chromium 浏览器 PoC

本仓库包含一个针对 CVE-2026-3909 的概念验证(PoC),可在 Chromium 浏览器中可靠触发。

背景

官方针对此漏洞的 Skia 修复仅包含一个简化的演示测试用例:

  • 官方演示:AtlasOobTest.cpp

它无法在真实的 Chromium 环境中运行。官方演示有意进行了限制,并省略了关键的触发条件。
本 PoC 基于官方演示构建,并经过修改,可在真实的 Chromium 浏览器环境中可靠触发该漏洞。

包含的补丁

本 PoC 包含对以下文件的修改:

1. raster_implementation.cc.patch

路径: <Chromium 根目录>/src/gpu/command_buffer/client/raster_implementation.cc

2. SkChromeRemoteGlyphCache.cpp.patch

路径: <Chromium 根目录>/src/third_party/skia/src/text/gpu/SkChromeRemoteGlyphCache.cpp

3. 其他

除了上述两个补丁文件外,您还可以在 DrawAtlas::hasID() 函数内部添加调试代码。 这样可以分析和观察中止(abort)被触发的原因。``` bool hasID(const skgpu::PlotLocator& plotLocator) { if (!plotLocator.isValid()) { return false; }

    uint32_t plot = plotLocator.plotIndex();
    uint32_t page = plotLocator.pageIndex();
    // patch code
    printf("[*] POC plot idx: %x fNumPlots: %x\n", plot, fNumPlots);
    // origin code
    uint64_t plotGeneration = fPages[page].fPlotArray[plot]->genID();
    uint64_t locatorGeneration = plotLocator.genID();
    return plot < fNumPlots && page < fNumActivePages && plotGeneration == locatorGeneration;
}
输出:```
[*] POC plot idx: 1f fNumPlots: 10

Git log

Chromium:``` commit e00a64ead1abef9447943efede7bc26362ac3797 (HEAD -> 146.0.7680.71, tag: 146.0.7680.71) Author: Roger McFarlane [email protected] Date: Mon Mar 9 12:52:01 2026 -0700

[M146-desktop-respin] Make LimitedLayerEntropyCostTracker time-aware.

This change modifies the LimitedLayerEntropyCostTracker to account for
the entropy cost of studies that are active at a specific evaluation
time. The evaluation time is passed to the tracker's constructor and is
used to check against the study's filter dates and Google web visibility
dates.

The current time for entropy evaluation is sourced from
VariationsIdsProvider.

(cherry picked from commit 2ec2c50b47686def251947a2675a207863803cac)

Bug: 490248046, 490432663
Change-Id: I3174730f35b037d533bf10b2b1d0531e3781acfe
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7639358
Reviewed-by: Alexei Svitkine <[email protected]>
Commit-Queue: Alexei Svitkine <[email protected]>
Cr-Original-Commit-Position: refs/heads/main@{#1595543}
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7637760
Bot-Commit: Rubber Stamper <[email protected]>
Cr-Commit-Position: refs/branch-heads/7680_65@{#23}
Cr-Branched-From: efe36a9d42443b4091a5be1be21e93ceff9b7a5e-refs/branch-heads/7680@{#1898}
Cr-Branched-From: 76b7d80e5cda23fe6537eed26d68c92e995c7f39-refs/heads/main@{#1582197}
## 构建参数```
# Set build arguments here. See `gn help buildargs`.
is_official_build = false
is_debug = true  
symbol_level = 2
v8_symbol_level = 2
blink_symbol_level = 2
is_component_build = false  
proprietary_codecs = true   
ffmpeg_branding = "Chrome"  
v8_enable_sandbox = true
dcheck_always_on = true
optimize_webui = true
target_os = "linux"
target_cpu = "x64"

用法

  1. 将两个补丁文件应用到存在漏洞的 Chromium 版本上。
  2. 打开浏览器 chrome <path>/trigger.html

中止```

gen/third_party/libc++/src/include/__memory/unique_ptr.h:578: libc++ Hardening assertion _checker.__in_bounds<deleter_type>(std::__to_address(_ptr), __i) failed: unique_ptr<T[]>::operator: index out of range Received signal 6

下载工具