New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 613605 link

Starred by 3 users

Issue metadata

Status: Untriaged
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug



Sign in to add a comment

Cookies with domain attribute duplicated with and without leading . in domain

Reported by mike.hen...@curvedental.com, May 20 2016

Issue description

Steps to reproduce the problem:
1. Sent set-cookie header in response to browser with no domain attribute
2. Send another set-cookie header to browser with same name and updated value
3. Check cookies in next request header.  Header contains two copies of cookie.  Looking in Chrome DevTools Resources' tab one cookies has leading . and the other does not.

What is the expected behavior?
Only one copy of the cookie is stored by the browser and returned via the Cookie header in subsequent requests.

What went wrong?
This is not reproducible on demand but generally happens within a few minutes of requests updating cookies on the device such as when the cookie is encrypted and has a sliding window expiration time within it.  The problem reproduces on two different Android devices both running Chrome 50.0.2661.89: a Samsung Galaxy Tab S2 and an Asus Zenphone.  The problem has not been seen in Chrome on the desktop.

Attached is a screenshot from Chrome DevTools showing the duplicated cookie.  A wireshark trace was captured on the server at the same time proving that the server never includes a domain attribute in the set-cookie header so the problem is not inconsistent behavior by the server.

Did this work before? N/A 

Chrome version: 50.0.2661.89  Channel: stable
OS Version: 5.0.2
Flash Version:
 
Screen Shot 2016-05-20 at 11.14.06 AM.png
131 KB View Download
Cc: mkwst@chromium.org est...@chromium.org
Components: Internals>Network>Cookies
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Owner: jww@chromium.org
Status: Assigned (was: Unconfirmed)
This seems unlikely to me to be a security vulnerability on its own.

jww@, I hear you're a cookie owner now. Could you take a look or delegate? :-)
Owner: mkwst@chromium.org
Cc: chlily@chromium.org mef@chromium.org mmenke@chromium.org morlovich@chromium.org
Labels: Hotlist-Cookies
Owner: ----
Status: Untriaged (was: Assigned)
(Unassigning myself, marking untriaged in preparation to retriage with folks who will do a better job taking care of cookies than I've been able to)

Sign in to add a comment