New issue
Advanced search Search tips

Issue 598537 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: ----
Type: Bug-Security



Sign in to add a comment

chrome 49.0.2623.108 within the suspicious search path vulnerability.

Reported by chenjie2...@gmail.com, Mar 29 2016

Issue description


chrome 49.0.2623.108 
 within the suspicious search path vulnerability. Local users  
kbdus.dll

 Trojan file in the current directory, and can be upgraded.
 
Apply CVE number

Comment 2 by wfh@chromium.org, Mar 29 2016

Labels: OS-Windows
Thank you for your report. Can you be more specific about the vulnerability? Where does kdbus.dll have to be placed?
look this picture
chrome.png
35.9 KB View Download

Comment 4 by wfh@chromium.org, Mar 29 2016

Labels: -Restrict-View-SecurityTeam
Status: Untriaged (was: Unconfirmed)
Anyone with the ability to write to Chrome's program directory is already running at a privilege level that they could bypass anything Chrome could do to prevent it e.g. place or modify operating system files, install a backdoor etc etc.

Chrome cannot defend itself against this type of attack and it is specifically excluded from our threat model. See https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-

oh , i know ..3q
Status: WontFix (was: Untriaged)
Project Member

Comment 7 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 8 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment