New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 595514 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: May 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: iOS
Pri: 2
Type: Bug-Security



Sign in to add a comment

Security: Navigating to "chrome://" URLs inside pdf (iOS)

Reported by chromium...@gmail.com, Mar 17 2016

Issue description

VERSION
Chrome Version: 49.0.2623.87 (stable 32-bit)
Operating System: iOS

REPRODUCTION CASE
On my machine (iOS) I can access to "chrome://" URLs via a pdf file and this is bad behavior. PDFs in iOS should not be allowed to navigate to "chrome://" URLs

This was fixed in  issue 528505 , but didn't fixed for iOS.
 
testcase.pdf
45.4 KB Download

Comment 1 by mea...@chromium.org, Mar 17 2016

Cc: lgar...@chromium.org
Lucas, can you check if the POC works on iOS? 

Comment 2 by mea...@chromium.org, Mar 18 2016

Components: UI>Browser>Navigation
Status: Untriaged (was: Unconfirmed)
Confirmed.

Comment 4 by mea...@chromium.org, Mar 18 2016

Cc: tsepez@chromium.org creis@chromium.org
Components: Internals>Plugins>PDF
Labels: Security_Severity-Low Security_Impact-Stable OS-iOS
Status: Available (was: Untriaged)
Thanks!
+creis and tsepez, any thoughts?
Project Member

Comment 5 by sheriffbot@chromium.org, May 4 2016

Labels: Pri-2
Any updates on this report?

Comment 7 by creis@chromium.org, May 13 2016

Owner: eugene...@chromium.org
eugenebut@: Did this bug get fixed as well as part of  issue 604086 ?
Cc: cma...@chromium.org
Status: Fixed (was: Available)
Yes, Claude could you please ask QA to retest.
Verified on 50.0.2661.9. Fixed.
Project Member

Comment 10 by sheriffbot@chromium.org, May 14 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Reward-topanel?
Cc: f...@chromium.org
CC felt@ to evaluate Comment #11.
Labels: reward-topanel
Should be fine to take it to the panel. It's not guaranteed that it will be rewarded, but it should be evaluated.

Comment 14 by f...@chromium.org, Jun 2 2016

Cc: -f...@chromium.org
Labels: -reward-topanel reward-unpaid Reward-500
Congratulations, the panel has decided to award $500 for this bug.  Our finance team will be in touch in the next few weeks with more details.
Cc: srikanthg@chromium.org
Labels: -reward-unpaid reward-inprocess
Project Member

Comment 18 by sheriffbot@chromium.org, Aug 20 2016

Labels: -Restrict-View-SecurityNotify
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 19 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 20 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment