New issue
Advanced search Search tips

Issue 596997 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Mar 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Download Protection Bypass

Reported by diosszab...@gmail.com, Mar 22 2016

Issue description


VERSION
Chrome Version: [49.0.2623.87] + [stable]
Operating System: [Microsoft Windows, 7 Ultimate, Sp1]
and               [Linux, ArchLinux]

REPRODUCTION CASE
After running my application without root access or admin rights, using Default or Guest profiles in google chrome or chromium in windows or linux (archlinux-2016.03.01-dual.iso) I can access any blacklisted websites such as https://testsafebrowsing.appspot.com/s/content.exe or http://pecs-harkany.hu/ because it turns off protection.
 
bug.zip
42.7 KB Download
Does your application modify chrome's settings?  Executing any user-priv application on the same machine is outside of chrome's threat model, and not eligible for VRP.
Labels: Needs-Feedback
Project Member

Comment 3 by ClusterFuzz, Mar 23 2016

Status: Assigned (was: New)
Yes, the application is only modifies the settings on the same machine.
Labels: -Restrict-View-Google -Needs-Feedback
Status: WontFix (was: Assigned)
ok, then this is working-as-intended.
Labels: Type-Bug

Comment 7 by vakh@chromium.org, Mar 10 2017

Labels: Restrict-View-SecurityTeam
For all Download Protection VRP bugs: removing label Restrict-View-Google and adding Restrict-View-SecurityTeam instead.
Project Member

Comment 8 by sheriffbot@chromium.org, Mar 11 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment