TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Google pushes emergency Chrome update to fix 8th zero-day in 2022

138 点作者 nixcraft超过 2 年前

4 条评论

ClosedPistachio超过 2 年前
Honest question: where do all of the new zero day vulnerabilities come from, new features/code? Just new bug detection techniques? I'd think over time entropy would get us to a point where there's hardly any vulnerabilities at all, but that's clearly not the case.
评论 #33741789 未加载
评论 #33741822 未加载
评论 #33743812 未加载
评论 #33745311 未加载
评论 #33741993 未加载
评论 #33741791 未加载
评论 #33743171 未加载
superjan超过 2 年前
<a href="https:&#x2F;&#x2F;nvd.nist.gov&#x2F;vuln&#x2F;detail&#x2F;CVE-2022-4135" rel="nofollow">https:&#x2F;&#x2F;nvd.nist.gov&#x2F;vuln&#x2F;detail&#x2F;CVE-2022-4135</a><p>“Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)”
评论 #33742472 未加载
muststopmyths超过 2 年前
I’m confused. If it’s a “heap buffer overflow in the GPU”, does this fix the chrome path to exploit and leave the driver for the manufacturer to patch ?<p>Or perhaps the bug is not actually “in the gpu “ ?
评论 #33742077 未加载
评论 #33741998 未加载
beardyw超过 2 年前
If they are fixing it is it a zero-day? What does that mean in this context?
评论 #33741880 未加载
评论 #33741893 未加载