Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

Example Analysis of remote Command execution vulnerability in Chrome 0day

2025-04-01 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Network Security >

Share

Shulou(Shulou.com)05/31 Report--

Editor to share with you the example analysis of Chrome 0day remote command execution vulnerabilities, I believe that most people do not know much about it, so share this article for your reference, I hope you can learn a lot after reading this article, let's go to know it!

For reference, study and use only

0x01, basic information

0day vulnerability in Google Chrome browser, which has been successfully replicated for the latest version.

The vulnerability environment is as follows

Browser version: 89.0.4389.114 (latest version)

Turn off the SandBox function of the browser, which is enabled by default

It should be noted that this vulnerability requires that the SandBox function of the browser be turned off, which is turned on by default.

In other words, the normal use of browsers will not be exploited by this vulnerability.

0x02, recurrence process 2.1 turn off sandbox mode

Open a shortcut to the browser and add-no-sandbox after the target

When you have finished modifying it, open the browser.

You can also go directly to the path of the browser and use the command to open the browser:

C:\ Program Files (x86)\ Google\ Chrome\ Application > chrome.exe-no-sandbox2.2 POC

Open the constructed attack page and the code can be executed.

The above is all the contents of the article "example Analysis of Chrome 0day remote Command execution vulnerabilities". Thank you for reading! I believe we all have a certain understanding, hope to share the content to help you, if you want to learn more knowledge, welcome to follow the industry information channel!

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Network Security

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report