New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 606101 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 181623
Owner:
Closed: May 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 1
Type: Bug-Security



Sign in to add a comment

Chrome for Android - Bad eliding of HTTP URLs allows for URL Spoofing

Reported by luan.her...@hotmail.com, Apr 23 2016

Issue description

VULNERABILITY DETAILS
For some reason the eliding of HTTP URLs behave differently from the HTTPS ones. 
If the URL utilizes HTTP, the alignment happens left-to-right, displaying first the subdomains and then the origin. With this, the attacker can craft a URL with several subdomains and the origin eventually will be hidden, like in: http.png (Full URL: http://www.developers.facebook.com.lbherrera.me)

This doesn't happens if HTTPS is utilized, as the alignment starts from right-to-left, displaying first the origin and then the subdomains, thus preventing the URL from being spoofed. See https.png (Full URL: http://www.developers.facebook.com.lbherrera.me)

VERSION
I tested on:
Chrome 49.0.2623.105 / Android 5.1.1
Chrome 49.0.2623.105 / Android 4.4.2

REPRODUCTION CASE
1. Access http://www.developers.facebook.com.lbherrera.me on Chrome for Android and check the omnibox.
2. Access https://www.developers.facebook.com.lbherrera.me on Chrome for Android and check the omnibox.
 
http.png
61.4 KB View Download
https.png
50.8 KB View Download

Comment 1 by vakh@chromium.org, Apr 23 2016

Cc: f...@chromium.org
Owner: palmer@chromium.org
palmer@ -- This may be WAI but I defer that decision to you.
Project Member

Comment 2 by ClusterFuzz, Apr 23 2016

Status: Assigned (was: Unconfirmed)

Comment 3 by vakh@chromium.org, Apr 25 2016

Components: UI>Browser>SafeBrowsing

Comment 4 by vakh@chromium.org, Apr 25 2016

Labels: Security_Impact-Stable
Labels: Security_Severity-Medium
Tentatively adding medium severity. Feel free to update this if you disagree.

Comment 6 by meacer@google.com, Apr 26 2016

Mergedinto: 181623
Status: Duplicate (was: Assigned)

Comment 7 by meacer@google.com, Apr 26 2016

Status: Assigned (was: Duplicate)
Hmm, this bug seems to differ between http and https. I'll let palmer comment.
Project Member

Comment 8 by ClusterFuzz, Apr 26 2016

Labels: Pri-1

Comment 9 by rsesek@chromium.org, Apr 26 2016

Labels: M-51

Comment 10 by vakh@chromium.org, May 6 2016

Labels: SafeBrowsing-Triaged
Project Member

Comment 11 by sheriffbot@chromium.org, May 7 2016

palmer: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 12 by sheriffbot@chromium.org, May 21 2016

palmer: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 13 by aarya@google.com, May 25 2016

Status: Duplicate (was: Assigned)
Labels: allpublic
Project Member

Comment 15 by sheriffbot@chromium.org, Jun 29 2017

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment