Sploitus

Exploit for Chrome Issue992914

githubexploit ยท 2026-08-21

Exploit Code

README124 lines
## https://sploitus.com/exploit?id=3E770CA1-3FD1-5CD8-90A6-AA20D9AD021C
# Chrome Issue 992914 โ€” 32-bit Port (Windows)

> **๋‹ค์‹œ ์˜ฌ๋ฆฌ๋Š” ์ด์œ  / Re-upload notice**
>
> **KR** โ€” 2019๋…„ Exodus Intelligence๊ฐ€ ๊ณต๊ฐœํ•œ 64๋น„ํŠธ ์ต์Šคํ”Œ๋กœ์ž‡์„ ์ œ๊ฐ€ **32๋น„ํŠธ Windows Chrome์šฉ์œผ๋กœ ํฌํŒ…**ํ•˜๋ฉด์„œ ์ •๋ฆฌํ•ด ๋‘” ์ž๋ฃŒ์ž…๋‹ˆ๋‹ค. ์˜ˆ์ „์— GitHub์— ์˜ฌ๋ ธ๋‹ค๊ฐ€ ๋‚ด๋ ธ๋˜ ์ €์žฅ์†Œ๋ฅผ, ๊ธฐ๋ก ๋ณด์กด ์ฐจ์›์—์„œ ๊ทธ๋Œ€๋กœ ๋‹ค์‹œ ๊ณต๊ฐœํ•ฉ๋‹ˆ๋‹ค. (์ž‘์„ฑ ์‹œ์ : 2019~2021, ๋‚ด์šฉ์€ ๋‹น์‹œ ๊ทธ๋Œ€๋กœ์ด๋ฉฐ ์ดํ›„ ๊ฐฑ์‹  ์—†์Œ)
>
> **EN** โ€” This is an old project: a **32-bit Windows port** of Exodus Intelligence's original 64-bit exploit for Chromium bug 992914. It was published here years ago, taken down, and is now **re-uploaded as-is for archival purposes**. Written 2019โ€“2021; unchanged since.

---

## ๊ฐœ์š” / Overview

**KR** โ€” Chromium V8์˜ **sealed/frozen elements kind type confusion** (Chromium bug **992914**) ์ทจ์•ฝ์  ์ต์Šคํ”Œ๋กœ์ž‡์ž…๋‹ˆ๋‹ค. ์›๋ณธ์€ Exodus Intelligence์˜ "patch-gapping" ์—ฐ๊ตฌ์—์„œ ๊ณต๊ฐœ๋œ **64๋น„ํŠธ** ๋ฒ„์ „์ด๊ณ , ์ด ์ €์žฅ์†Œ๋Š” ์ด๋ฅผ **32๋น„ํŠธ Chrome (Windows)** ํ™˜๊ฒฝ์— ๋งž๊ฒŒ ๋ณ€ํ™˜ํ•œ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

**EN** โ€” The bug is a type confusion in V8's handling of sealed/frozen element kinds (Chromium bug **992914**). Exodus published a working **64-bit** exploit as part of their patch-gapping research; this repository contains a **32-bit Windows port** of that exploit, together with the slide deck describing how the conversion was done.

* **Original 64-bit exploit author / ์›๋ณธ 64๋น„ํŠธ ์ต์Šคํ”Œ๋กœ์ž‡ ์ œ์ž‘:** Exodus Intelligence
* **32-bit port / 32๋น„ํŠธ ๋ณ€ํ™˜:** this repository
* **Tested on / ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ:** Windows 10, **32-bit** Chrome 76.0.3809.100 / 76.0.3809.132

## ์ด ๋ฌธ์„œ์˜ ๋ชฉ์  / Purpose

**KR** โ€” ๋‹จ์ˆœํžˆ ๋™์ž‘ํ•˜๋Š” ์ต์Šคํ”Œ๋กœ์ž‡์„ ํ•˜๋‚˜ ๋” ๊ณต๊ฐœํ•˜๋ ค๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ, **64๋น„ํŠธ ์ต์Šคํ”Œ๋กœ์ž‡์„ 32๋น„ํŠธ๋กœ ์ง์ ‘ ์ด์‹ํ•ด ๋ณด๋Š” ๊ณผ์ •์„ ํ†ตํ•ด ํฌ๋กฌ(V8) ์ต์Šคํ”Œ๋กœ์ž‡์— ๋Œ€ํ•œ ์ดํ•ด์˜ ํญ์„ ๋„“ํžˆ๋Š” ๊ฒƒ**์ด ์ด ์ž๋ฃŒ์˜ ๋ชฉ์ ์ž…๋‹ˆ๋‹ค.

๋‚จ์ด ๋งŒ๋“  64๋น„ํŠธ ์ต์Šคํ”Œ๋กœ์ž‡์„ ๊ทธ๋Œ€๋กœ ์‹คํ–‰ํ•ด ๋ณด๋Š” ๊ฒƒ๊ณผ, ๊ทธ๊ฒƒ์„ ๋‹ค๋ฅธ ์•„ํ‚คํ…์ฒ˜๋กœ ์˜ฎ๊ธฐ๋Š” ๊ฒƒ์€ ์š”๊ตฌ๋˜๋Š” ์ดํ•ด๋„๊ฐ€ ๋‹ค๋ฆ…๋‹ˆ๋‹ค. ํฌํŒ…์„ ํ•˜๋ ค๋ฉด ๊ฐ ๋‹จ๊ณ„๊ฐ€ *์™œ* ๊ทธ๋ ‡๊ฒŒ ๋™์ž‘ํ•˜๋Š”์ง€๋ฅผ ์•Œ์•„์•ผ ํ•˜๊ณ , ๊ทธ ๊ณผ์ •์—์„œ ์ž์—ฐ์Šค๋Ÿฝ๊ฒŒ ๋‹ค์Œ์„ ํŒŒ๊ณ ๋“ค๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

* V8์˜ ๊ฐ์ฒด ๋ฉ”๋ชจ๋ฆฌ ๋ ˆ์ด์•„์›ƒ โ€” Map, elements, properties backing store๊ฐ€ ํž™์— ์–ด๋–ป๊ฒŒ ๋ฐฐ์น˜๋˜๋Š”๊ฐ€
* 32๋น„ํŠธ์—์„œ์˜ SMI/ํฌ์ธํ„ฐ ํƒœ๊น…๊ณผ double ํ‘œํ˜„ โ€” ์™œ ํ•˜๋‚˜์˜ double(64๋น„ํŠธ) ์•ˆ์— 32๋น„ํŠธ ํฌ์ธํ„ฐ ๋‘ ๊ฐœ๋ฅผ ๋„ฃ์–ด ๋‹ค๋ค„์•ผ ํ•˜๋Š”๊ฐ€
* 64๋น„ํŠธ ๊ธฐ์ค€์œผ๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋œ ์˜คํ”„์…‹ยท์ธ๋ฑ์Šค๋ฅผ 32๋น„ํŠธ ๊ธฐ์ค€์œผ๋กœ ์–ด๋–ป๊ฒŒ ๋‹ค์‹œ ๊ณ„์‚ฐํ•˜๋Š”๊ฐ€
* `WebAssembly.Instance` โ†’ `WasmExportedFunctionData` โ†’ RWX ํŽ˜์ด์ง€๋กœ ์ด์–ด์ง€๋Š” ์ฝ”๋“œ ์‹คํ–‰ ์ฒด์ธ์ด ์•„ํ‚คํ…์ฒ˜๋ณ„๋กœ ์–ด๋–ป๊ฒŒ ๋‹ฌ๋ผ์ง€๋Š”๊ฐ€
* d8๊ณผ ์‹ค์ œ ๋ธŒ๋ผ์šฐ์ €์—์„œ ํž™ ์ƒํƒœ๊ฐ€ ์–ด๋–ป๊ฒŒ ๋‹ฌ๋ผ์ง€๊ณ , ๊ทธ๊ฒƒ์ด ์ต์Šคํ”Œ๋กœ์ž‡ ์‹ ๋ขฐ์„ฑ์— ์–ด๋–ค ์˜ํ–ฅ์„ ์ฃผ๋Š”๊ฐ€

์ฒจ๋ถ€ํ•œ ๋ฐœํ‘œ ์ž๋ฃŒ(`.pptx`)๋Š” ์ด ๋ณ€ํ™˜ ๊ณผ์ •์„ ๋‹จ๊ณ„๋ณ„๋กœ ๋”ฐ๋ผ๊ฐ€๋ฉฐ ์ •๋ฆฌํ•œ ๊ฒƒ์œผ๋กœ, ๊ฒฐ๊ณผ๋ฌผ์ธ ์ฝ”๋“œ๋ณด๋‹ค **๊ฑฐ๊ธฐ๊นŒ์ง€ ๊ฐ€๋Š” ๊ณผ์ •**์— ์ดˆ์ ์„ ๋งž์ถ”๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

**EN** โ€” The point of this repository is not to publish yet another working exploit. It is to use the **port from 64-bit to 32-bit as a vehicle for broadening one's understanding of Chrome/V8 exploitation**.

Running someone else's 64-bit exploit and moving that exploit to a different architecture demand very different levels of understanding. Porting it requires knowing *why* each step works the way it does, and in doing so you end up digging into:

* V8's object memory layout โ€” how the Map, elements, and properties backing stores are arranged on the heap
* SMI/pointer tagging and double representation on 32-bit โ€” why a single 64-bit double has to carry and be manipulated as two 32-bit pointers
* How offsets and indices hardcoded for 64-bit must be recomputed for 32-bit
* How the `WebAssembly.Instance` โ†’ `WasmExportedFunctionData` โ†’ RWX page code-execution chain differs between architectures
* How the heap state differs between d8 and the real browser, and what that does to exploit reliability

The attached slide deck (`.pptx`) walks through the conversion step by step; it focuses on **the reasoning that leads to the result** rather than on the finished code.

## ํŒŒ์ผ ๊ตฌ์„ฑ / Files

| File | ์„ค๋ช… / Description |
| --- | --- |
| `exp_32bit.html` | **KR** ์ต์Šคํ”Œ๋กœ์ž‡ ์ง„์ž…์ . `print()` / `hex()` / `hexdump()` ํ—ฌํผ๋ฅผ ์ •์˜ํ•˜๊ณ  `chrome_992914_32bit.js`๋ฅผ ๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.**EN** Exploit entry point. Defines the `print()` / `hex()` / `hexdump()` helpers and loads `chrome_992914_32bit.js`. |
| `chrome_992914_32bit.js` | **KR** ๋ธŒ๋ผ์šฐ์ €์šฉ 32๋น„ํŠธ ์ต์Šคํ”Œ๋กœ์ž‡ ๋ณธ์ฒด (type confusion โ†’ addrof/AAR/AAW โ†’ WASM RWX โ†’ shellcode).**EN** The 32-bit exploit itself, for the browser (type confusion โ†’ addrof/AAR/AAW โ†’ WASM RWX โ†’ shellcode). |
| `d8_32bit_ex.js` | **KR** d8(V8 ์…ธ)์—์„œ ๋””๋ฒ„๊น…์šฉ์œผ๋กœ ์“ฐ๋˜ ๋ณ€ํ˜•๋ณธ. ๋กœ๊ทธ๊ฐ€ ๋” ์ž์„ธํ•˜๊ณ  ์ผ๋ถ€ ๋‹จ๊ณ„๊ฐ€ ์ฃผ์„ ์ฒ˜๋ฆฌ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.**EN** A variant used for debugging under d8 (the V8 shell): more verbose logging, with some stages commented out. |
| `How_to_convert_Chrome_Issue992914_exploit_to_32-bit_on_Windows.pptx` | **KR** 64๋น„ํŠธ โ†’ 32๋น„ํŠธ ๋ณ€ํ™˜ ๊ณผ์ •์„ ์ •๋ฆฌํ•œ ๋ฐœํ‘œ ์ž๋ฃŒ (์•ฝ 34MB).**EN** Slide deck documenting the 64-bit โ†’ 32-bit conversion (~34 MB). |

## ๋™์ž‘ ๋ฐฉ์‹ ์š”์•ฝ / How it works

**KR**

1. Sealed/frozen element kind ํƒ€์ž… ํ˜ผ๋™์„ ์ด์šฉํ•ด ์ธ์ ‘ํ•œ `float_array`์˜ ๊ธธ์ด/๋ฐ์ดํ„ฐ ํฌ์ธํ„ฐ๋ฅผ ๊นจ๋œจ๋ฆฝ๋‹ˆ๋‹ค.
2. ๊นจ์ง„ float ๋ฐฐ์—ด๋กœ **relative OOB read/write**๋ฅผ ์–ป๊ณ , ์ด๋ฅผ `addrof` ํ”„๋ฆฌ๋ฏธํ‹ฐ๋ธŒ๋กœ ํ™•์žฅํ•ฉ๋‹ˆ๋‹ค.
3. 32๋น„ํŠธ์—์„œ๋Š” ํ•˜๋‚˜์˜ double(64๋น„ํŠธ) ์•ˆ์— ๋‘ ๊ฐœ์˜ 32๋น„ํŠธ ํฌ์ธํ„ฐ๊ฐ€ ๋“ค์–ด๊ฐ€๋ฏ€๋กœ, `setHighUint32()` / `float_to_low_32bit()` ๊ฐ™์€ ํ—ฌํผ๋กœ ์ƒยทํ•˜์œ„ 32๋น„ํŠธ๋ฅผ ๋‚˜๋ˆ  ๋‹ค๋ฃจ๋ฉฐ **์ž„์˜ ์ฃผ์†Œ ์ฝ๊ธฐ/์“ฐ๊ธฐ(AAR/AAW)** ๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.
4. `WebAssembly.Instance` โ†’ `WasmExportedFunctionData` โ†’ instance ์˜ค๋ธŒ์ ํŠธ๋ฅผ ๋”ฐ๋ผ๊ฐ€ **RWX ํŽ˜์ด์ง€ ์ฃผ์†Œ**๋ฅผ ์–ป์Šต๋‹ˆ๋‹ค.
5. RWX ํŽ˜์ด์ง€์— ์…ธ์ฝ”๋“œ๋ฅผ ์“ฐ๊ณ , ์ต์ŠคํฌํŠธ๋œ WASM ํ•จ์ˆ˜(`wfunc()`)๋ฅผ ํ˜ธ์ถœํ•ด ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ๋ณธ ์…ธ์ฝ”๋“œ๋Š” PEB ์›Œํ‚น์œผ๋กœ `WinExec`๋ฅผ ์ฐพ์•„ **`calc`** ๋ฅผ ์‹คํ–‰ํ•˜๋Š” 32๋น„ํŠธ ์ฝ”๋“œ์ž…๋‹ˆ๋‹ค (`chrome_992914_32bit.js`์˜ `shellcode` ๋ฐฐ์—ด). ํž™ ์ƒํƒœ์— ๋”ฐ๋ผ ์‹คํŒจํ•  ์ˆ˜ ์žˆ์–ด ์ตœ๋Œ€ 500ํšŒ ๋ฐ˜๋ณตํ•˜๊ณ , ๊ทธ๋ž˜๋„ ์‹คํŒจํ•˜๋ฉด 2์ดˆ ๋’ค ํŽ˜์ด์ง€๋ฅผ ๋ฆฌ๋กœ๋“œํ•ด ์žฌ์‹œ๋„ํ•ฉ๋‹ˆ๋‹ค.

**EN**

1. The sealed/frozen element kind type confusion is used to corrupt the length/data pointer of an adjacent `float_array`.
2. The corrupted float array yields a **relative OOB read/write**, which is extended into an `addrof` primitive.
3. On 32-bit, a single 64-bit double holds two 32-bit pointers, so helpers such as `setHighUint32()` / `float_to_low_32bit()` split it into high and low halves to build **arbitrary address read/write (AAR/AAW)**.
4. Following `WebAssembly.Instance` โ†’ `WasmExportedFunctionData` โ†’ the instance object yields the address of an **RWX page**.
5. The shellcode is written into that RWX page and executed by calling the exported WASM function (`wfunc()`).

The default shellcode is 32-bit code that walks the PEB to resolve `WinExec` and launches **`calc`** (see the `shellcode` array in `chrome_992914_32bit.js`). Because success depends on heap state, the exploit retries up to 500 times, then reloads the page after 2 seconds and tries again.

## ์‹คํ–‰ ๋ฐฉ๋ฒ• / Usage

**KR**

1. **32๋น„ํŠธ** Chrome 76.0.3809.100 ๋˜๋Š” 76.0.3809.132 ๋ฅผ `--no-sandbox` ๋กœ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.
2. ์ด ๋””๋ ‰ํ„ฐ๋ฆฌ๋ฅผ ๋กœ์ปฌ ์›น์„œ๋ฒ„๋กœ ํ˜ธ์ŠคํŒ…ํ•ฉ๋‹ˆ๋‹ค. (์˜ˆ: `python -m http.server 8000`)
3. ๋ธŒ๋ผ์šฐ์ €์—์„œ `http://localhost:8000/exp_32bit.html` ์— ์ ‘์†ํ•ฉ๋‹ˆ๋‹ค.
4. ์„ฑ๊ณตํ•˜๋ฉด ๊ณ„์‚ฐ๊ธฐ๊ฐ€ ๋œน๋‹ˆ๋‹ค. ์ง„ํ–‰ ๋กœ๊ทธ๋Š” DevTools ์ฝ˜์†”์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

**EN**

1. Launch **32-bit** Chrome 76.0.3809.100 or 76.0.3809.132 with `--no-sandbox`.
2. Host this directory with a local web server (e.g. `python -m http.server 8000`).
3. Browse to `http://localhost:8000/exp_32bit.html`.
4. On success, the calculator pops. Progress messages are visible in the DevTools console.

```
chrome.exe --no-sandbox
python -m http.server 8000
```

d8๋กœ ๋””๋ฒ„๊น…ํ•  ๋•Œ / For debugging under d8:

```
d8.exe --allow-natives-syntax d8_32bit_ex.js
```

## ์ฃผ์˜ / Disclaimer

**KR**

* ๋Œ€์ƒ ์ทจ์•ฝ์ ์€ **2019๋…„์— ์ด๋ฏธ ํŒจ์น˜**๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ตœ์‹  Chrome์—์„œ๋Š” ๋™์ž‘ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
* ์ด ์ฝ”๋“œ๋Š” **์—ฐ๊ตฌยท๊ต์œก ๋ชฉ์ **์œผ๋กœ๋งŒ ๊ณต๊ฐœํ•ฉ๋‹ˆ๋‹ค. ๋ฐ˜๋“œ์‹œ ๋ณธ์ธ ์†Œ์œ ์ด๊ฑฐ๋‚˜ ๋ช…์‹œ์ ์œผ๋กœ ํ—ˆ๊ฐ€๋ฐ›์€ ๊ฒฉ๋ฆฌ๋œ ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ์—์„œ๋งŒ ์‹คํ–‰ํ•˜์„ธ์š”.
* ์…ธ์ฝ”๋“œ๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์œผ๋ฏ€๋กœ ์‹ค ์‚ฌ์šฉ ์ค‘์ธ ๋จธ์‹ ์—์„œ ์‹คํ–‰ํ•˜์ง€ ๋งˆ์‹œ๊ณ , VM์—์„œ ํ…Œ์ŠคํŠธํ•˜์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค.
* ์›๋ณธ ์ต์Šคํ”Œ๋กœ์ž‡์˜ ์ €์ž‘๊ถŒ/ํฌ๋ ˆ๋”ง์€ Exodus Intelligence์— ์žˆ์Šต๋‹ˆ๋‹ค.

**EN**

* The vulnerability was **patched back in 2019**. This does not work against current Chrome.
* Published for **research and educational purposes only**. Run it only in an isolated test environment you own or have explicit permission to test.
* It contains shellcode โ€” do not run it on a machine you actually use; test in a VM.
* Credit and copyright for the original exploit belong to Exodus Intelligence.

---

*Originally written 2019โ€“2021. Re-uploaded unchanged. / 2019~2021๋…„ ์ž‘์„ฑ, ๋‚ด์šฉ ๋ณ€๊ฒฝ ์—†์ด ์žฌ์—…๋กœ๋“œ.*