漏洞关键信息 类型: 漏洞 优先级: P1 严重性: S1 状态: Fixed CVE: 2020-15998 漏洞详情 描述: The Open-IPC-Call will create a device_handle and push its raw-pointer into handles_. Frequent calls to Open-IPC-Call will cause the old device_handle to be replaced and destroyed. But it will not clean up the handles_. Its raw pointer will be accessed when the device is unplugged or removed, and the UAF will be triggered. 版本: Chrome 版本: M86 稳定版 操作系统: Windows, Mac 复现案例 选择一个 USB 设备,当设备被拔出或移除时,UAF 将被触发。 崩溃信息 错误类型: 浏览器 崩溃状态: 查看 asan 文件 致谢信息 发现者: Leecraso 和 Guang Gong of 360 Alpha Lab, 使用 360 BugCloud