New issue
Advanced search Search tips

Issue 606638 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: XSS chrome rendering considerations are not caused by a Filter XSS bypass

Reported by xiaopig...@gmail.com, Apr 26 2016

Issue description

Then the other details are in the attachment.


Chrome Version: [50.0.2661.87] + [beta]


 
bug.docx
12.7 KB Download

Comment 1 by rsesek@chromium.org, Apr 26 2016

I'm sorry, but can you please post your report in English rather than Chinese? Ideally the writeup would be in the bug tracker rather than in a .docx file, with your PoC files attached as .html or as a .zip.
Project Member

Comment 2 by ClusterFuzz, May 2 2016

Labels: Untriaged-2
Components: Blink>SecurityFeature
The claim here appears to be that the XSS Auditor can be bypassed if the injection point is at the end of the page and represents a partial HTML tag, the Auditor will ignore the tag as invalid/incomplete, but that invalid/incomplete tag will get "fixed up" by the HTML normalization process later, creating valid HTML that leads to script execution. 

Getting raw POC files would probably be even more useful than an English-language document.
I roughly google translated the document. The situation being described involves a document.write. If I understand correctly, XSS Auditor does not attempt to protect against DOM based XSS, right? If so, then this bug is probably WontFix.
Right, can we find out if it's a document fragment (document.write) vs a full page load?
The injected script is via document.write in the example.
Status: WontFix (was: Unconfirmed)
reporter - if you can give us an example that doesn't use document.write, please feel free to re-open.
Yes, it could be a false report.
Project Member

Comment 9 by sheriffbot@chromium.org, Aug 9 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment