New issue
Advanced search Search tips

Issue 606550 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2016
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Chrome WriteAV

Reported by msvulnre...@gmail.com, Apr 25 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Safari/537.36 Edge/13.10586

Steps to reproduce the problem:
on Win7 (32bit or 64bit):

- make sure chrome.exe is NOT running (otherwise the bug does NOT repro)

- attach appverif.exe to chrome.exe (for instance as follows:

    appverif -enable heaps exceptions -for chrome.exe

  )

- in an (elevated/as-admin) command prompt, run

    "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" index-small.html

What is the expected behavior?
Chrome should not crash

What went wrong?
Chrome crashes

Did this work before? N/A 

Chrome version: 49.0.2623.110  Channel: n/a
OS Version: 10.0
Flash Version: Shockwave Flash 21.0 r0

I have crash dumps available if you'd like them (they are over the max attachment size)
 
index-small.html
83 bytes View Download

Comment 1 by wfh@chromium.org, Apr 25 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
Chrome sandbox does not function with page heap enabled. This is by design.

Comment 2 by rickyz@chromium.org, Apr 26 2016

By the way, if you are trying to enable page heap in order to fuzz chrome, we recommend using ASAN instead (we have builds available to download at https://www.chromium.org/developers/testing/addresssanitizer).
Thank you for your reply. Please note that if you turn off the sandbox with the ‘—no-sandbox’ option advertised in https://www.chromium.org/developers/testing/page-heap-for-chrome and run chrome.exe under AppVerifier (PageHeap) with a sample html file, chrome.exe still crashes, this time with a ReadAV (= buffer overflow, read access violation).
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment