New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 619355 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit 28 days ago
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: XSS issue in Google Mail

Reported by suhas0...@gmail.com, Jun 12 2016

Issue description

VULNERABILITY DETAILS
XSS vector gets executed in Google Mail, Google Chrome Version 51.0.2704.84 on 12th Jun,2016 CET

VERSION
Chrome Version: 51.0.2704.84 stable
Operating System: Windows 7

REPRODUCTION CASE
1. Login to your Google account using Google Chrome browser (Tested with Version 51.0.2704.84 on 12th Jun,2016 CET)
2. Install Mail Track extension to Google chrome Browser. (https://chrome.google.com/webstore/detail/mailtrack-for-gmail/ndnaehgpjlnokgebbaldlmgkapkpjkkb?hl=en)
3. Now visit https://www.google.com/maps/
4. Click menu and go to Your places -> Maps and click create maps
5. Create map with title as <IMG SRC=x onerror="javascript:alert('Hacked by Suhas Gaikwad ;)');">
6. Share map with Victim or self.
7. Onload of gmail XSS gets executed.

Tested with following vectors
a. <IMG SRC="javascript:alert('XSS');" onerror="javascript:alert(document.cookie);">
b. "><img src=x onerror=alert(1)/>
c. <IMG SRC=x onerror="javascript:alert(document.domain);">
d. <img src=x onerror=window.open('https://www.google.com/');>

Or Simple way , attacker can able to send email to victim with subject as <IMG SRC=x onerror="javascript:alert(document.domain);"> OR <img src=x onerror=window.open('https://www.google.com/');>
and it will get executed. 

Please refer video at : https://youtu.be/cjUWbz0vy1s

Attack senario :
Ask victim to install Google chrome - MailTrack extension and create Google map or send email with XSS vector as a title to victim. e.g. :  <IMG SRC=x onerror="javascript:alert(document.domain);">

Also using xss vector as  <img src=x onerror=window.open('https://www.google.com/');> , attacker can able to do OpenRedirect in Gmail.

This issue is because of MailTrack extension, disabling MailTrack extension mitigate XSS vulnerability. 

Let me know if you need more details. Thank you.
 
Cc: mea...@chromium.org
Components: Platform>Extensions
Labels: Security_Severity-Medium Security_Impact-None
This appears to require the MailTrack extension, so it's not a vulnerability in Chrome directly.

meacer -- How do we report/flag extensions that cause unexpected security issues?

Comment 2 by mea...@chromium.org, Jun 13 2016

Cc: ackermanb@chromium.org
ackermanb: Can you help carry out the communication with the extension developer? Thanks.
Sure, I will coordinate with the policy folks.

Comment 4 by suhas0...@gmail.com, Jun 13 2016

@Team, Thank you for quick update. MailTrack extension used by more than 400000+ users so its risk for all users. Attacker can able to take over victims Google account via XSS.Is there any way to handle such security issues in Google Chrome browser extensions in future. Let me know if you need any details from my end.
Cc: -ackermanb@chromium.org
Owner: ackermanb@chromium.org
Status: Fixed (was: Unconfirmed)
The developer pushed a fix to this yesterday. I ran it through the steps to reproduce and didn't see the vulnerability anymore. Thanks for the report!
Project Member

Comment 6 by sheriffbot@chromium.org, Jun 17 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify

Comment 7 by suhas0...@gmail.com, Jun 17 2016

@Team, Thank you for update. Is my report eligible for reward / Hall of fame / swag from Google Chrome ? Thank you.
Labels: reward-ineligible
Sorry I'm afraid it's not, and we've got to be careful of things like http://dilbert.com/strip/1995-11-13 :-)

But thank you very much for the report - if you use your skills to find problems in Chrome itself or other Google apps/sites you very might well be.  Keep up the good work!
Project Member

Comment 9 by sheriffbot@chromium.org, Sep 23 2016

Labels: -Restrict-View-SecurityNotify
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment