New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 596342 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Mar 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug-Security



Sign in to add a comment

Add APK and file downloads to Safe Browsing checsk

Reported by resea...@nightwatchcybersecurity.com, Mar 20 2016

Issue description

Steps to reproduce the problem:
Right now downloading an APK or other files does not increment the counter in safe browsing. It seems that the browser on Android is only checking websites but not files

What is the expected behavior?
Bad files should be blocked

What went wrong?
This file:
https://testsafebrowsing.appspot.com/s/content.exe

Is not marked as bad on Android. Download an APK does not increment the counter either in:

chrome://histograms/SBClientDownload.CheckDownloadStats

Did this work before? No 

Chrome version: 49.0.2623.91 Official Build  Channel: n/a
OS Version: 6.0.1
Flash Version:
 

Comment 1 by mea...@chromium.org, Mar 21 2016

Components: Services>Safebrowsing
Owner: nparker@chromium.org
Status: Assigned (was: Unconfirmed)
Nathan: Can you please triage? Thanks.
Cc: asanka@chromium.org
Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Assigned)
Thanks for the report.

This is WAI -- downloads on Android are checked by Android rather than by Chrome (asanka correct me if this is not precise).

Comment 3 by asanka@chromium.org, Mar 21 2016

Cc: qin...@chromium.org
Yeah. I believe on Android, APKs are verified at install time regardless of how they were downloaded.

Project Member

Comment 4 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic
Cc: ya...@nightwatchcybersecurity.com

Sign in to add a comment