New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 609282 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: XSS is rendered before being redirected to an actual site that has an XSS payload

Reported by shipco...@gmail.com, May 4 2016

Issue description

VULNERABILITY DETAILS
I decided to report a vulnerability wherein an XSS payload is being executed and rendered before being redirected to an actual site. By adding <script>alert('hello world') in a website (example: evil.com) cached by Google for example, the payload is executed prior to being taken to evil.com.

Here is a sample wherein I used a defacement page of someone as an example:
1. Visit https://www.google.com.ph/search?sourceid=chrome-psyapi2&rlz=1C5CHFA_enPH690PH690&ion=1&espv=2&ie=UTF-8&q=LEYTE_PR1D3&oq=Ley&aqs=chrome.1.69i57j69i59j69i61j0l2j69i60.2788j0j7 
2. If that doesn't work you can just type LEYTE_PR1D3 in the search field / engine
3. Click on the first website (in my case atozjob.com/images - attached is the screenshot) that is ranked one - XSS should pop up before being redirected (this is not open redirection)

In Firefox, it is not like this. I am taken to the website before the XSS payload is rendered.

VERSION
Chrome Version: Version 50.0.2661.94 (64-bit)

Operating System: Mac OS X El Capitan Version 10.11.14

REPRODUCTION CASE
Please include a demonstration of the security bug, such as an attached
HTML or binary file that reproduces the bug when loaded in Chrome. PLEASE
make the file as small as possible and remove any content not required to
demonstrate the bug.


 
render.jpg
227 KB View Download
Cc: palmer@chromium.org a...@chromium.org f...@chromium.org
Components: Security>UX
It doesn't seem ideal that the alert dialog is being displayed before the page is rendered, but it doesn't block the navigation. I'm not too worried about this overall.

Adding a few people who might have different opinions.
Status: Available (was: Unconfirmed)
Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Available)
WontFix'ing this since no one else raised any concerns. Feel free to reopen if you disagree.
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic
Components: -Security>UX
Labels: Team-Security-UX
Security>UX component is deprecated in favor of the Team-Security-UX label

Sign in to add a comment