¡¾Îó²îͨ¸æ¡¿Google Chrome ɳÏäÌÓÒÝÎó²î(CVE-2025-6558)

Ðû²¼Ê±¼ä 2025-07-17

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Google Chrome ɳÏäÌÓÒÝÎó²î

CVE   ID

CVE-2025-6558

Îó²îÀàÐÍ

ɳÏäÌÓÒÝ

·¢Ã÷ʱ¼ä

2025-07-17

Îó²îÆÀ·Ö

8.8

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

ÒÑ·¢Ã÷


Google Chrome ÊÇÓɹȸ迪·¢µÄ¿çÆ½Ì¨ÍøÒ³ä¯ÀÀÆ÷ £¬£¬£¬£¬ÒÔÆäËÙÂÊ¡¢Çå¾²ÐԺ;«Á·µÄ½çÃæ¶øÖøÃû¡£¡£¡£Ëü»ùÓÚ¿ªÔ´µÄChromiumÏîÄ¿ £¬£¬£¬£¬Ö§³ÖÏÖ´úÍøÒ³±ê×¼ £¬£¬£¬£¬¾ßÓÐǿʢµÄÀ©Õ¹ÐÔ¡£¡£¡£ChromeµÄɳÏäÊÖÒÕ¿ÉÒÔÏÞÖÆÍøÒ³ÖеĶñÒâ´úÂë £¬£¬£¬£¬ÔöÇ¿ä¯ÀÀÆ÷µÄÇå¾²ÐÔ¡£¡£¡£Ëü»¹ÌṩÁËͬ²½¹¦Ð§ £¬£¬£¬£¬ÔÊÐíÓû§ÔÚ¶à¸ö×°±¸¼äͬ²½ÊéÇ©¡¢ÀúÊ·¼Í¼µÈÊý¾Ý¡£¡£¡£±ðµÄ £¬£¬£¬£¬Chrome°´ÆÚ¸üР£¬£¬£¬£¬ÐÞ¸´ÒÑÖªÎó²î²¢ÔöÇ¿¹¦Ð§ £¬£¬£¬£¬ÊÇÈ«ÇòʹÓÃ×îÆÕ±éµÄä¯ÀÀÆ÷Ö®Ò»¡£¡£¡£


2025Äê7ÔÂ17ÈÕ £¬£¬£¬£¬°ÙÀÖ²©¼¯ÍÅVSRC¼à²âµ½Google Chrome±£´æÉ³ÏäÌÓÒÝÎó²î¡£¡£¡£Éæ¼°ANGLEºÍGPU×é¼þµÄ²»¿ÉÐÅÊäÈëÑé֤ȱ·¦¡£¡£¡£¸ÃÎó²îÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâHTMLÒ³Ãæ £¬£¬£¬£¬Èƹýä¯ÀÀÆ÷µÄɳÏä»úÖÆ £¬£¬£¬£¬¿ÉÄܶԵײãϵͳ¾ÙÐжñÒâ²Ù×÷¡£¡£¡£ANGLE£¨ÏÕЩÍâµØÍ¼ÐβãÒýÇæ£©×÷ΪChromeäÖȾÒýÇæÓë×°±¸Ìض¨Í¼ÐÎÇý¶¯Ö®¼äµÄ·­Òë²ã £¬£¬£¬£¬Îó²îʹÓÿÉʹ¹¥»÷Õßͨ¹ýÀÄÓóõ¼¶GPU²Ù×÷ʵÏÖɳÏäÌÓÒÝ £¬£¬£¬£¬»ñÈ¡¸üÉîÌõÀíµÄϵͳ»á¼ûȨÏÞ¡£¡£¡£´ËÎó²îÒÑÔÚÏÖʵ¹¥»÷Öб»Ê¹Óà £¬£¬£¬£¬¿ÉÄÜÒý·¢Ä¿µÄ¹¥»÷ £¬£¬£¬£¬¹¥»÷Õß½öÐè»á¼û¶ñÒâÍøÕ¾¼´¿ÉDZÔÚÍ»ÆÆä¯ÀÀÆ÷Çå¾²ÏÞÖÆ¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Google Chrome Windows < 138.0.7204.157
Google Chrome Mac < 138.0.7204.157
Google Chrome Linux < 138.0.7204.157


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾ £¬£¬£¬£¬½¨Ò龡¿ìÉý¼¶ÖÁ×îа汾
Google Chrome Windows >= 138.0.7204.157
Google Chrome Mac >= 138.0.7204.157
Google Chrome Linux >= 138.0.7204.157


ÏÂÔØÁ´½Ó£ºhttps://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£


3.3 ͨÓý¨Òé


?°´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬£¬£¬£¬ïÔ̭ϵͳÎó²î £¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
?ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ £¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ £¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£
?ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
?ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£
?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html
https://nvd.nist.gov/vuln/detail/CVE-2025-6558
https://thehackernews.com/2025/07/urgent-google-releases-critical-chrome.html