The .safariextz are not checked by Download Protection
Reported by
resea...@nightwatchcybersecurity.com,
Apr 1 2016
|
||||||||
Issue descriptionVERSION Chrome Version: 49.0.2623.110 Operating System: Mac OS X 10.11.4 REPRODUCTION CASE Safari extension files should be checked. This is mitigated by a warning that Safari prompts users before installing extensions.
,
Apr 4 2016
,
Apr 4 2016
lgarron -- Do you know about how Safari warns before installing an extension from the file system? Is it sufficiently low-friction (scary) that Chrome should block them? Related: crbug.com/599879
,
Apr 5 2016
Yes, Safari does ask before installing the extension. "You can also get extensions directly from your favorite developers. When you download an extension from a developer, you get a file that ends with .safariextz. Double-click the file to install the extension. It isn't signed or hosted by Apple, so Safari asks you to confirm that you trust the source and want to install the extension." Source: https://support.apple.com/en-us/HT203051
,
Apr 6 2016
,
Apr 11 2016
research@nightwatchcybersecurity.com: Thanks for reporting this issue. According to the rules of reward program: "The file type on disk must lead to non-sandboxed code execution after minimal user interaction with the file." Source: https://www.google.com/about/appsecurity/chrome-rewards/index.html Since installing a .safariextz that's not been signed by Apple requires the user to accept a prompt designed to defeat such installation, the interaction cannot be considered minimal. Therefore, this bug does not qualify for the reward.
,
Mar 9 2017
,
Mar 10 2017
For all Download Protection VRP bugs: removing label Restrict-View-Google and adding Restrict-View-SecurityTeam instead.
,
Mar 11 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by ClusterFuzz
, Apr 1 2016