New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 600606 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Download Protection: ICC files not checked on Windows

Reported by resea...@nightwatchcybersecurity.com, Apr 5 2016

Issue description

VERSION
Chrome Version: 49.0.2623.110 (Official Build) m (32-bit)
Operating System: Windows 2012 R2; version 6.3.9600

REPRODUCTION CASE
ICC profiles are not checked and are installed silently on Windows. ICC files in the past have carried malicious code. This also affects ICM, CAMP, CDMP and GMMP extensions on Windows, and ICC on Mac. We can try to provide a patch if needed.

Past vulnerabilities:
https://www.kb.cert.org/vuls/id/980078
https://www.kb.cert.org/vuls/id/720742


Sample file:
https://github.com/lovell/sharp/blob/master/icc/sRGB_IEC61966-2-1_black_scaled.icc

 
Labels: -Restrict-View-SecurityTeam Restrict-View-Google
Owner: ----

Comment 3 by vakh@chromium.org, Apr 21 2016

Status: WontFix (was: New)
It is outside Chrome's threat model to know what application is registered to handle different filetypes, what version of that application is installed, and whether it is patched.
Cc: ya...@nightwatchcybersecurity.com

Comment 5 by vakh@chromium.org, Mar 10 2017

Labels: -Restrict-View-Google Restrict-View-SecurityTeam
For all Download Protection VRP bugs: removing label Restrict-View-Google and adding Restrict-View-SecurityTeam instead.
Project Member

Comment 6 by sheriffbot@chromium.org, Mar 11 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment