Issue metadata
Sign in to add a comment
|
Security: XSS using Google Chrome PDF handler
Reported by
iqaba...@gmail.com,
Mar 7 2016
|
||||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS Its possible to execute arbitrary scripts using the chrome pdf handler VERSION Chrome Version: [49.0.2623.75 m] + [stable] Operating System: Windows 8.1, 64bit REPRODUCTION CASE Open the attached PDF using chrome and simply right click the text '@qab' and choose 'open in new tab', javascript is executed.
,
Mar 7 2016
,
Mar 7 2016
While it is true that this will result in the execution of javascript, it's not XSS.
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by jialiul@chromium.org
, Mar 7 2016