New issue
Advanced search Search tips

Issue 606892 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

XSS in Chrome Browser

Reported by priyansh...@gmail.com, Apr 26 2016

Issue description

Hello,

Myself Priyanshu Sahay working as Cyber Security researcher. Just want to inform you that your Chrome Browser are vulnerable to Cross Site Scripting attack.

I found XSS & DOM XSS vulnerability into Chrome browser. Please fix this vulnerability as soon as possible..


VULNERABILITY DETAILS
Just paste the following exploit codes in the Chrome Browser you will get PopUp

Exploit Code:

1. XSS:

data:text/html;base64,PHNjcmlwdD5hbGVydCgvWFNTLyk8L3NjcmlwdD4=

2. DOM XSS: 

data:text/html;base64,PHNjcmlwdD5wcm9tcHQoL1hTUy8pPC9zY3JpcHQ+


Just paste the above exploit codes in the Chrome Browser you will get PopUp

Please find the attachment for proof of concept (POC) .. 

VERSION
Chrome Version: Latest
Operating System: Windows And MAC


Please find the attachment for proof of concept (POC) 

Regards
Priyanshu Sahay


 
Chrome Browser XSS.png
77.0 KB View Download
Chrome Browser DOM XSS.png
81.0 KB View Download

Comment 1 by rsesek@chromium.org, Apr 26 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
What you are describing is not an XSS nor a security vulnerability in Chrome. This is merely executing the HTML and script code included in a data URI.
Ok, Thanks for Update!
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment