New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 601250 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: May 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Download Protection: .SAVER files not checked on Mac OS

Reported by resea...@nightwatchcybersecurity.com, Apr 6 2016

Issue description

VERSION
Chrome Version: 49.0.2623.87 Official Build
Operating System: Mac OS X El Capitan, version 10.11.3

REPRODUCTION CASE
.SAVER files on Mac OS are screen savers and are not currently checked by Chrome, like SCR files are on Windows. This is somewhat mitigated by Gatekeeper which stops users from installing non-App store files, but the same logic applies to .APP and .DMG files which are checked by Chrome. Example file:

https://github.com/winterbe/github-matrix-screensaver/releases

We can try to provide a patch if covered by Patch rewards
 
There is also an install prompt which does not happen for .APP files but will happen to DMG files. This is a directory so it would need to be inside some compressed file.

This also applies to .QTZ Files
We rechecked this - being that .SAVER is a directory and needs to be carried inside a ZIP file, this is not relevant for VRP.

QTZ files open with QuickTime and a warning, also not relevant.

Comment 3 by vakh@chromium.org, May 6 2016

Labels: SafeBrowsing-Triaged
Owner: vakh@chromium.org

Comment 4 by vakh@chromium.org, May 27 2016

Status: WontFix (was: Unconfirmed)
Thanks for filing this issue.

As you mentioned, downloading the linked file causes the histogram at chrome://histograms/SBClientDownload.CheckDownloadStats to record this download, which makes this issue ineligible for Download Protection VRP.
Cc: ya...@nightwatchcybersecurity.com

Comment 6 by vakh@chromium.org, Mar 10 2017

Labels: -Restrict-View-Google Restrict-View-SecurityTeam
For all Download Protection VRP bugs: removing label Restrict-View-Google and adding Restrict-View-SecurityTeam instead.
Project Member

Comment 7 by sheriffbot@chromium.org, Mar 11 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment