New issue
Advanced search Search tips

Issue 638457 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Browser locks up while trying to copy highlighted Ruby code via right mouse click

Reported by brian.ca...@gmail.com, Aug 17 2016

Issue description

VULNERABILITY DETAILS
Highlighting Ruby code and trying to copy it via right click causes the browser to quit responding temporarily. Repeatedly clicking the right mouse button can trigger a hard lock.

VERSION
Chrome Version: 54.0.2824.0 dev-m (64-bit)
Operating System: Windows 8.1 

REPRODUCTION CASE
While hunting for obfuscated code to fuzz Ruby with, I came across http://www.rubyinside.com/advent2006/4-ruby-obfuscation.html and while it looks ordinary, if you highlight the section entitled `Display Primes Less Than 1000` starting at $e="" and ending with eval $e. (Highlighting the parts that start with # nullify the issue for whatever reason we're going to conclude later on. After you highlight said text, right click to copy the text. You can't. Because it feels like Chrome is trying to actually eval $e. Repeatedly right clicking on the highlighted area will eventually hard lock the browser, requiring an `End Task`. Unable to replicate in IE or Firefox. 

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: browser locks up
Crash State: nothing available
Client ID (if relevant): 

 
Status: WontFix (was: Unconfirmed)
Thanks for reporting and the detailed repro steps. These are super helpful. 

I tried on current stable 52.0.2743.82 too, I can see noticeable delay between right mouth clicking and the showing of context menu.
 
But this issue seems already fixed. the latest canary version 54.0.2831.0 works just fine. 




Project Member

Comment 2 by sheriffbot@chromium.org, Nov 24 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment