New issue
Advanced search Search tips

Issue 629055 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 2016
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug-Security



Sign in to add a comment

mechanism of intent for chrome is not safe and easy to be fished

Reported by cruise1...@gmail.com, Jul 18 2016

Issue description

Steps to reproduce the problem:
1.  set the switch in Settings - Security Unknown sources true;
2. build and make an unsafe Android app which has the same packageName as the official app(Obviously this fake app's signature is different from the official one);
3. Common user installs the fake app  instead of the official app;
4. Through the intent for chrome, chrome jumps to the fake app

What is the expected behavior?
if the app is not official , then chrome shouldn't jump to it through the intent in the website;

What went wrong?
At present , Chrome only supports  verifying with the packageName in intent , rather than the signature of the app, this step is not safe.
Obviously , chrome should and also is willing to make itself safe, such as App link introduced in Android 6.0 system, which is only supporting the https condition.

Did this work before? Yes In China Android market, since Android 4.x, this trick is popular, it happens all the time. 

Chrome version: 51.0.2704.103  Channel: stable
OS Version: 6.0
Flash Version: Shockwave Flash 22.0 r0

In China, most users couldn't access the service of Google Play Store, so they can only get and install app via USB or downloading  from internet, which can't verify the app safe and official.I think this issue may occur in other countries .
 

Comment 1 by ta...@google.com, Jul 18 2016

Status: WontFix (was: Unconfirmed)
Chrome security doesn't cover a physically-local attack. Please see the faq here: https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-

Thanks
Project Member

Comment 2 by sheriffbot@chromium.org, Oct 25 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment