Issue metadata
Sign in to add a comment
|
Security: XSS chrome rendering considerations are not caused by a Filter XSS bypass
Reported by
xiaopig...@gmail.com,
Apr 26 2016
|
||||||||||||||||||||
Issue descriptionThen the other details are in the attachment. Chrome Version: [50.0.2661.87] + [beta]
,
May 2 2016
,
May 2 2016
The claim here appears to be that the XSS Auditor can be bypassed if the injection point is at the end of the page and represents a partial HTML tag, the Auditor will ignore the tag as invalid/incomplete, but that invalid/incomplete tag will get "fixed up" by the HTML normalization process later, creating valid HTML that leads to script execution. Getting raw POC files would probably be even more useful than an English-language document.
,
May 2 2016
I roughly google translated the document. The situation being described involves a document.write. If I understand correctly, XSS Auditor does not attempt to protect against DOM based XSS, right? If so, then this bug is probably WontFix.
,
May 2 2016
Right, can we find out if it's a document fragment (document.write) vs a full page load?
,
May 2 2016
The injected script is via document.write in the example.
,
May 2 2016
reporter - if you can give us an example that doesn't use document.write, please feel free to re-open.
,
May 3 2016
Yes, it could be a false report.
,
Aug 9 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by rsesek@chromium.org
, Apr 26 2016