New issue
Advanced search Search tips

Issue 591674 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Found Bug while running a JavaScript Code in console window of chrome browser.

Reported by mishra0s...@gmail.com, Mar 3 2016

Issue description

VULNERABILITY DETAILS
Whenever I am trying to execute a Javascript code (find as an attachment) in your's chrome browser developer tool console, it is getting crashed and disconnected from the browser.

VERSION
Chrome Version: [48.0.2564.116] + [stable]
Operating System: [Windows 7, Enterprise, 32-Bit ( 6.1, Build 7601) ]

REPRODUCTION CASE
When you try to run/execute this JavaScript code (Code is attached as an attachment file) in console window of Developer tools available in chrome browser. It will crash the developer tool and gets disconnected from chrome browser.
Even, all the web pages that are open in browser gets disconnected and unavailable.
If you are already login into the browser, you will automatically get logout from it.

FOR CRASHES, ADDITIONAL INFORMATION
Type of crash: Browser
 
Num2Words.js
1.1 KB View Download
Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
Thanks for reporting mishra0shashank!
There are logic bugs in your code which causes endless recursion. If the code takes up too much resources (a.k.a memory) and reach browser's resource limit, browser will crash/malfunction. This does not seem like a new vulnerability but rather work as intended. 
 
Thanks for updating on this issue & sorry for creating trouble in your busy
work schedule.

Thanks & Regards,
Shashank





Shashank Mishra
Information Technology Engineer
Dev Bhoomi Institute of Technology, Dehradun
*Contact : *+91-9528505442
*E-mail : *mishra0shashank@gmail.com

On Fri, Mar 4, 2016 at 2:45 AM, jialiul@chromium.org via Monorail <
monorail@chromium.org> wrote:
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment