New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 629668 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 624214
Owner:
Closed: Aug 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: iOS
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: Address bar spoofing with U+FE70 on iOS

Reported by chromium...@gmail.com, Jul 19 2016

Issue description

VERSION
Chrome Version: 51.0.2704.104
Operating System: iOS

REPRODUCTION CASE
1. Navigate to http://tinyurl.com/pnsp55f
2. Address bar shows google.com but the page's hostname is http://127.0.0.1

 
This doesn't affect Windows (I tested that first), so I will try iOS as the reporter mentions.
The bug being reported appears to be that the long URL gets truncated in the address bar, and the user only sees "www.google.com." Let me see who can look at this on the iOS side.
Owner: rohitrao@chromium.org
Status: Available (was: Unconfirmed)
Rohit, can you take a look at this? We need to figure out if we can reasonably avoid this problem. 
Cc: kerrnel@chromium.org
Able to reproduce the bug on Android (also iOS) with http://xn--nebl.xn--9dbq2a/example.com

Omnibox shows: "example.com‬/רע.קום"
Project Member

Comment 6 by sheriffbot@chromium.org, Jul 22 2016

Status: Assigned (was: Available)
Labels: OS-Android OS-iOS
Cc: pkasting@chromium.org
Components: UI>Browser>Omnibox
Labels: Security_Severity-High Security_Impact-Stable
Cc: -pkasting@chromium.org
CCing me on iOS bugs probably does not make sense since I have no knowledge of iOS or the omnibox implementation there.
Labels: -OS-Android
Ok, the original URL "http://tinyurl.com/pnsp55f" reproduces on iOS but not Android for me.

The other URL, "http://xn--nebl.xn--9dbq2a/example.com" reproduces on both iOS and Android.
Is that means they're two different issues?
We need to triage this and debug further to find out. It could still be the same issue.
Project Member

Comment 14 by sheriffbot@chromium.org, Jul 23 2016

Labels: M-52
Project Member

Comment 15 by sheriffbot@chromium.org, Jul 23 2016

Labels: Pri-1
Cc: justincohen@chromium.org
I can't repro in the latest canary, so I think this is the same underlying bug as  Issue 624214 .
Mergedinto: 624214
Status: Duplicate (was: Assigned)
Cc: mgiuca@chromium.org
Project Member

Comment 19 by sheriffbot@chromium.org, Nov 9 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment