New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 600908 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: May 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug



Sign in to add a comment

Download Protection: MPKG file not checked on Mac OS

Reported by resea...@nightwatchcybersecurity.com, Apr 6 2016

Issue description

VERSION
Chrome Version: 49.0.2623.87 Official Build
Operating System: Mac OS X El Capitan, version 10.11.3

REPRODUCTION CASE
MPKG are another alias for PKG files in Mac OS, which are used by the Mac installer. To reproduce, take any .PKG file, rename it to .MPKG and double click. While Mac OS does show a warning for non-app store files, the same warning is shown for .PKG files which are checked by Chrome. MPKG file processing should match.

Sample PKG file:
https://github.com/Yubico/yubico.github.com/blob/master/yubikey-neo-manager/releases/yubikey-neo-manager-0.2.2-mac.pkg

We can try to provide a patch if eligible for Patch Rewards

 
Labels: -Restrict-View-SecurityTeam Restrict-View-Google
Owner: ----
Attaching patch
mpkg.patch
2.9 KB Download

Comment 5 by vakh@chromium.org, May 6 2016

Labels: SafeBrowsing-Triaged
Owner: vakh@chromium.org
Just wondering if this issue is still being looked at

Comment 7 by vakh@chromium.org, May 27 2016

Cc: jialiul@chromium.org
Labels: Pri-2
Status: Available (was: New)
Thanks for reporting the issue. I am able to reproduce the issue locally.
A .mpkg file is a meta .PKG file that can link to other .PKG files so we should treat them identically.

jialiul@ -- would you like to take this on?
Cc: nparker@chromium.org
+nparker@, Do you mind providing a sample CL of adding new a extension to your shining dynamic file extension list? 
Cc: vakh@chromium.org
Owner: nparker@chromium.org
Status: Started (was: Available)
Yup, I'll create a cl for this
@nparker: We are attaching a patch using the new dynamic file extension system
mpkg_new.patch
2.3 KB Download
Ah.  I already have a CL pending: https://codereview.chromium.org/2010333004.  Yours was more complete though -- I was missing the GetDownloadType() change.  Thanks!
Status: Fixed (was: Started)

Comment 14 by vakh@chromium.org, Jun 1 2016

Labels: reward-to-sb-panel

Comment 15 by vakh@chromium.org, Jun 7 2016

Labels: -reward-to-sb-panel reward-unpaid Reward-500
Is there a reason why the bounty is not $1,000 like the usual SB bypass?

Comment 17 by vakh@chromium.org, Jun 7 2016

The amount for a baseline report for Download Protection bypass is $500, as listed on [1].

The final amount is always chosen at the discretion of the reward panel.
In this case, the panel decided that the report was baseline quality and the patch trivial.

[1]: https://www.google.com/about/appsecurity/chrome-rewards/index.html
Labels: -reward-unpaid reward-inprocess
We haven't heard from anyone regarding the reward
Labels: -Restrict-View-Google -Reward-500 reward-500
Cc: ya...@nightwatchcybersecurity.com

Comment 22 by vakh@chromium.org, Mar 10 2017

Labels: Restrict-View-SecurityTeam
For all Download Protection VRP bugs: removing label Restrict-View-Google and adding Restrict-View-SecurityTeam instead.
Project Member

Comment 23 by sheriffbot@chromium.org, Mar 11 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment