New issue
Advanced search Search tips

Issue 634705 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 634080
Owner: ----
Closed: Aug 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Showing google URL on address bar but when form in completed then informations will sent to attacker site

Reported by tahir.vb...@gmail.com, Aug 5 2016

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
This vulnerability allow attackers to show google URL and then show about:blank please see attached video. By using this vulnerability an attacker can show legal google URL in chrome but when USER enter his google login credentials then credentials will send to attacker site.

VERSION
Chrome Version: Version 51.0.2704.103 m
Operating System: Windows 7 Service Pack 1

REPRODUCTION CASE

URL:  http://jsfiddle.net/dy4swq4o/show/   


HTML:  
HTML is attached in file
 
proof video.mp4
1.1 MB View Download
proof.html
126 KB View Download
Mergedinto: 634080
Status: Duplicate (was: Unconfirmed)
This looks identical to  bug 634080 :
The page opens a new tab to www.google.com, but at the same time modifies the newly opened page contents, which reverts back to about:blank. Quoting from that bug:

"This is indeed working as intended.  It was the behavior we added in  issue 9682  to allow us to show the pending URL when there's no possible attacker content visible below it.  As soon as something accesses the initial blank document, we revert to showing the last committed URL, which is about:blank in the new window.
."
Labels: -Restrict-View-SecurityTeam
Project Member

Comment 3 by sheriffbot@chromium.org, Nov 12 2016

Labels: allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment