Google Chrome 释放后使用漏洞,由 S4E 团队报告
总漏洞赏金:6,000 美元
这是以下内容的 PoC(概念验证):
Google 博客文章:
https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop_20.html
要求:无需任何工具,只需在旧版 Google Chrome [91.0.4472.77] + [稳定版](官方构建)(64位)中运行一个 HTML 文件即可。
poc-exploit.html(该漏洞在 Google Chrome 91 及更低版本中有效,已在 92+ 版本中修复)
提到的漏洞由“Security For Everyone 团队”报告。