New issue
Advanced search Search tips

Issue 631965 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: javascript modules not load and wrong on window object

Reported by dotadota...@gmail.com, Jul 27 2016

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.
javascript modules  not load and wrong on window object

VERSION
Chrome Version: [52.0.2743.82 (64-bit)] update at 2016/07/27
Operating System: [OSX 10.10, Windows8.1]

REPRODUCTION CASE
Please include a demonstration of the security bug, such as an attached
HTML or binary file that reproduces the bug when loaded in Chrome. PLEASE
make the file as small as possible and remove any content not required to
demonstrate the bug.

Chrome Version       : 52.0.2743.82 (64-bit)
URL :all web site
Behavior in Safari 4.x/5.x:No
Behavior in Firefox 3.x/4.x:No

(1)Accsess Any Site Then, First of all  Show Chrome developer tool and Select Sources Tab(This step is probably important)
(2)Hide Chrome developer tool 
(3)Reload Site(F5 on Win ⌘R on Mac)   at the same time show Chrome developer tool
     Then,  For Example , $(jQuery) is another object. Site's javascript is undefined.      
(4)This problem is likely to lead to any vulnerability
     →f12 induction on Windows and keyfook reload(window.location.reload())

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

 
correct.png
40.7 KB View Download
wrong.png
39.6 KB View Download

Comment 1 by rickyz@chromium.org, Jul 27 2016

Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Status: WontFix (was: Unconfirmed)
Hi, this doesn't look like a security bug.

If you look at the context that the console applies to (the dropdown to the right of the "Preserve Log" checkbox, you'll see that the two screenshots show the console on two different contexts. This is why the definition of $ is different.
Sorry, Preserve Log can't leave a log.
Before reload, Hide Chrome developer tool .
never reproduce without it.

Sign in to add a comment