The Hacker News¤Ï4·î8Æü(¸½ÃÏ»þ´Ö)¡¢¡ÖGoogle Chrome Adds V8 Sandbox - A New Defense Against Browser Attacks¡×¤Ë¤ª¤¤¤Æ¡¢Google Chrome¤ËV8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤¬Äɲ䵤줿¤ÈÅÁ¤¨¤¿¡£V8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤ÎƳÆþ¤Ë¤è¤ê¿®Íê¤Ç¤­¤Ê¤¤JavaScript¥³¡¼¥É¤¬Ê¬Î¥¤µ¤ì¡¢¥á¥â¥êÇË»¤¬¥Û¥¹¥È¥×¥í¥»¥¹Æâ¤Ë¹­¤¬¤ë¤³¤È¤òËɻߤǤ­¤ë¡£

Google Chrome Adds V8 Sandbox - A New Defense Against Browser Attacks

¡ûV8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹Æ³Æþ¤Î·Ð°Þ

º£²óGoogle Chrome¤ËƳÆþ¤µ¤ì¤¿V8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤Ï¡ÖThe V8 Sandbox · V8¡×¤Ç¾Ü¤·¤¯²òÀ⤵¤ì¤Æ¤¤¤ë¡£V8¤ÏGoogle¤¬³«È¯¤¹¤ë¥ª¡¼¥×¥ó¥½¡¼¥¹¤ÎJIT Virtual Machine¤ÎJavaScript¥¨¥ó¥¸¥ó¤Ç¡¢V8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤ÏV8ÍѤΥ¤¥ó¥×¥í¥»¥¹¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤È¤µ¤ì¤ë¡£

²òÀâ¤Ë¤è¤ë¤È¡¢2021ǯ¤«¤é2023ǯ¤Ëȯ¸«¤µ¤ì¤¿¤¹¤Ù¤Æ¤ÎChrome¤Î¥¨¥¯¥¹¥×¥í¥¤¥È¤Ï¡¢¥ê¥â¡¼¥È¥³¡¼¥É¼Â¹Ô(RCE: Remote Code Execution)¤Î¤¿¤á¤Ë°­ÍѤµ¤ì¤¿¥ì¥ó¥À¥é¡¼¥×¥í¥»¥¹¤Î¥á¥â¥êÇË»¤ÎÀȼåÀ­¤«¤é»Ï¤Þ¤Ã¤Æ¤ª¤ê¡¢¤½¤Î60%¤ÏV8¤ÎÀȼåÀ­¤À¤Ã¤¿¤È¤¤¤¦¡£¤³¤ì¤éÀȼåÀ­¤Ï¸ÅŵŪ¤Ê¥á¥â¥êÇ˲õ¤Î¥Ð¥°(²òÊü¸å»ÈÍÑ¡¢Èϰϳ°¥¢¥¯¥»¥¹¤Ê¤É)¤Ç¤Ï¤Ê¤¯¡¢Èù̯¤Ê¥í¥¸¥Ã¥¯¤ÎÌäÂê¤Î¤¿¤á¡¢´û¸¤Î¥á¥â¥ê°ÂÁ´¥½¥ê¥å¡¼¥·¥ç¥ó(Rust¤Î»ÈÍѤä¥á¥â¥ê¤Î¥¿¥°ÉÕ¤±¤Ê¤É)¤Ç¤ÏÂнè¤Ç¤­¤Ê¤¤¤È¤·¤Æ¤¤¤ë¡£

¤¿¤À¡¢¤³¤ì¤éÀȼåÀ­¤Î¤Û¤Ü¤¹¤Ù¤Æ¤Ë¤Ï¶¦ÄÌÅÀ¤¬Â¸ºß¤¹¤ë¤È¤¤¤¦¡£¤½¤ì¤Ï¡¢¥³¥ó¥Ñ¥¤¥é¡¼¤È¥é¥ó¥¿¥¤¥à¤¬V8 HeapObject¥¤¥ó¥¹¥¿¥ó¥¹¤ËÂФ·¤ÆÇÓ¾Ū¤ËÆ°ºî¤¹¤ë¤¿¤á¡¢¥á¥â¥êÇ˲õ¤ÏV8¥Ò¡¼¥×Æâ¤ÇȯÀ¸¤¹¤ë¤È¤¤¤¦ÅÀ¡£³«È¯¼Ô¤Ï¤³¤Î¶¦ÄÌÅÀ¤ËÃåÌܤ·¡¢ÌäÂêȯÀ¸»þ¤Ë±Æ¶Á¤ò·Ú¸º¤¹¤ëÊýË¡¤È¤·¤ÆV8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤òƳÆþ¤·¤¿¡£

¡ûV8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹

V8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤Ï¥ª¥Ú¥ì¡¼¥Æ¥£¥ó¥°¥·¥¹¥Æ¥à¤Ë¤ª¤±¤ë¥«¡¼¥Í¥ë¶õ´Ö¤È¥æ¡¼¥¶¡¼¶õ´Ö¤Î¥á¥â¥ê¡¼Ê¬Î¥¤ÈƱ¤¸³µÇ°¤È¤µ¤ì¤ë¡£Æ°ºî¤È¤·¤Æ¤Ï¼Â¹Ô¤µ¤ì¤ë¥³¡¼¥É¤ò¥×¥í¥»¥¹¤Î²¾ÁÛ¥¢¥É¥ì¥¹¶õ´Ö¤Î¥µ¥Ö¥»¥Ã¥È¤ËÀ©¸Â¤·¡¢¥×¥í¥»¥¹¤Î»Ä¤ê¤Î¶õ´Ö¤Ø¤Î¥¢¥¯¥»¥¹¤ò¥Ö¥í¥Ã¥¯¤¹¤ë¡£¶ñÂÎŪ¤Ë¤ÏÀ¸¤Î¥Ý¥¤¥ó¥¿¡¼¤ò¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤Î¥Ù¡¼¥¹°ÌÃÖ¤«¤é¤Î¥ª¥Õ¥»¥Ã¥È¤ËÊÑ´¹¡¢¤Þ¤¿¤Ï¥µ¥ó¥É¥Ü¥Ã¥¯¥¹³°¤Î¥Ý¥¤¥ó¥¿¥Æ¡¼¥Ö¥ë¤Î¥¤¥ó¥Ç¥Ã¥¯¥¹¤ËÊÑ´¹¤¹¤ë¤³¤È¤Ç¼Â¸½¤¹¤ë¡£

V8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤Î³µÇ°¿Þ ¡¡°úÍÑ¡§V8¥×¥í¥¸¥§¥¯¥È

V8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤Ï¾­ÍèŪ¤Ë¥Ï¡¼¥É¥¦¥§¥¢¥µ¥Ý¡¼¥È¤òÍøÍѤ·¤Æ¼ÂÁõ²Äǽ¤À¤¬¡¢¸½ºß¤ÏɬÍפʥϡ¼¥É¥¦¥§¥¢¼ÂÁõ¤¬¤Ê¤¤¤¿¤á¥½¥Õ¥È¥¦¥§¥¢¤Ç¼ÂÁõ¤·¤Æ¤¤¤ë¤È¤¤¤¦¡£¤·¤«¤·¤Ê¤¬¤é¡¢¼ÂÁõ¥³¥¹¥È¤ÏÄ㤤¤È¤·¤Æ¤ª¤ê¡¢¥Ñ¥Õ¥©¡¼¥Þ¥ó¥¹¤Ø¤Î±Æ¶Á¤Ï°ìÈÌŪ¤Ê¥ï¡¼¥¯¥í¡¼¥É¤Ë¤ª¤¤¤ÆÌó1%°Ê²¼¤È¤·¤Æ¤¤¤ë¡£¤Ê¤ª¡¢V8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤òÍøÍѤ¹¤ë¤Ë¤Ï1¥Æ¥é¥Ð¥¤¥È¤Î²¾ÁÛ¥¢¥É¥ì¥¹¶õ´Ö¤¬É¬Íפʤ¿¤á¡¢64¥Ó¥Ã¥È¥·¥¹¥Æ¥à¤¬É¬¿Ü¾ò·ï¤È¤Ê¤ë¡£

V8¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤ÏGoogle Chrome ¥Ð¡¼¥¸¥ç¥ó123¤«¤é¥Ç¥Õ¥©¥ë¥È¤ÇÍ­¸ú²½¤µ¤ì¤ë¡£¤Þ¤¿¡¢Chrome¤ÎÀȼåÀ­Êó¾©¥×¥í¥°¥é¥à(VRP: Vulnerability Reward Program)¤ÎÂоݤˤâÄɲ䵤ì¤ë(»²¹Í¡§¡ÖChrome Vulnerability Reward Program Rules - Rules - About - Google Bug Hunters¡×)¡£