0-day vulnerability in Chrome discovered through analysis of changes in the V8 engine

Researchers from Exodus Intelligence was demonstrated have identified a weak point in the vulnerability patching process within the Chrome/Chromium codebase. The issue stems from Google revealing that the fixes pertain to security problems only after the release, but
they add code to the repository to address the vulnerability in the V8 engine before the release is published. For a while, the fixes undergo testing, creating a window during which the vulnerability is resolved in the codebase and available for analysis, but it remains unfixed on user systems.

In examining the changes made to the repository, researchers noted an addition on February 19 prevents the invocation of credential.helper for URLs that contain and within three days were able to prepare exploit, targeting current Chrome releases (the published exploit did not include components for bypassing sandbox isolation). Google promptly released released Chrome version 80.0.3987.122, addressing the issue related to the proposed exploit vulnerability (CVE-2020-6418). The vulnerability was initially identified by Google engineers and caused by a type handling issue in the JSCreate operation, which can be exploited through the Array.pop or Array.prototype.pop methods. Notably, a similar issue was fixed in Firefox last summer.

Researchers also noted an ease in exploit creation due to the inclusion of Chrome 80 a mechanism for pointer packing (instead of storing the full 64-bit value, only the unique lower bits of the pointer are kept, significantly reducing memory consumption in the heap). For example, certain structures at the beginning of the heap, such as the built-in functions table, 'native context' objects, and root objects of the garbage collector, are now placed at predictable and writable packed addresses.

Interestingly, nearly a year ago, Exodus Intelligence demonstrated a similar exploit creation possibility based on reviewing the public V8 patch log, but evidently no significant conclusions were drawn. In the place of researchers,
malicious actors or intelligence agencies could have leveraged the exploit, potentially allowing them to secretly exploit the vulnerability for days or even weeks before the next Chrome release.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster