New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 600592 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Download Protection: IMESX files are not checked

Reported by resea...@nightwatchcybersecurity.com, Apr 5 2016

Issue description

VERSION
Chrome Version: 49.0.2623.110 (Official Build) m (32-bit)
Operating System: Windows 2012 R2; version 6.3.9600

REPRODUCTION CASE
IMESX files can be used to add a search provider to Microsoft IME and are not checked. Windows does show a warning. We can provide a patch.

Sample file:
snow-white.cocolog-nifty.com/first/msime/google.imesx

 
Labels: -Restrict-View-SecurityTeam Restrict-View-Google
Owner: ----

Comment 3 by vakh@chromium.org, Apr 20 2016

Status: WontFix (was: New)
I'm unable to reproduce this issue. When I open the link you shared, Chrome doesn't offer to download the file. Instead, Chrome renders it as a text file.
Marking as WontFix for now.

Please re-open the bug with the steps to reproduce this problem more clearly.
@vakh - mime type issue, try this:

https://theowl.xyz/cr/600592/google.imesx

Comment 5 by vakh@chromium.org, Apr 20 2016

Thanks for sharing that link.

As you mentioned in the bug description, Windows shows a warning to the user. That makes this case outside the scope of the SafeBrowsing VRP program.
Cc: ya...@nightwatchcybersecurity.com

Comment 7 by vakh@chromium.org, Mar 10 2017

Labels: -Restrict-View-Google Restrict-View-SecurityTeam
For all Download Protection VRP bugs: removing label Restrict-View-Google and adding Restrict-View-SecurityTeam instead.
Project Member

Comment 8 by sheriffbot@chromium.org, Mar 11 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment