New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 599880 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug



Sign in to add a comment

The .safariextz are not checked by Download Protection

Reported by resea...@nightwatchcybersecurity.com, Apr 1 2016

Issue description

VERSION
Chrome Version: 49.0.2623.110
Operating System: Mac OS X 10.11.4

REPRODUCTION CASE
Safari extension files should be checked. This is mitigated by a warning that Safari prompts users before installing extensions.

 
Project Member

Comment 1 by ClusterFuzz, Apr 1 2016

Status: Assigned (was: New)
Labels: -Type-Bug-Security Type-Bug
Cc: lgar...@chromium.org
Labels: Pri-2
lgarron -- Do you know about how Safari warns before installing an extension from the file system?  Is it sufficiently low-friction (scary) that Chrome should block them?

Related:  crbug.com/599879 

Comment 4 by vakh@chromium.org, Apr 5 2016

Yes, Safari does ask before installing the extension.

"You can also get extensions directly from your favorite developers. When you download an extension from a developer, you get a file that ends with .safariextz. Double-click the file to install the extension. It isn't signed or hosted by Apple, so Safari asks you to confirm that you trust the source and want to install the extension."

Source: https://support.apple.com/en-us/HT203051
Owner: vakh@chromium.org

Comment 6 by vakh@chromium.org, Apr 11 2016

Status: WontFix (was: Assigned)
research@nightwatchcybersecurity.com: Thanks for reporting this issue.

According to the rules of reward program:
"The file type on disk must lead to non-sandboxed code execution after minimal user interaction with the file."
Source: https://www.google.com/about/appsecurity/chrome-rewards/index.html

Since installing a .safariextz that's not been signed by Apple requires the user to accept a prompt designed to defeat such installation, the interaction cannot be considered minimal.

Therefore, this bug does not qualify for the reward.
Cc: ya...@nightwatchcybersecurity.com

Comment 8 by vakh@chromium.org, Mar 10 2017

Labels: -Restrict-View-Google Restrict-View-SecurityTeam
For all Download Protection VRP bugs: removing label Restrict-View-Google and adding Restrict-View-SecurityTeam instead.
Project Member

Comment 9 by sheriffbot@chromium.org, Mar 11 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment