Issue metadata
Sign in to add a comment
|
Security: Browser locks up while trying to copy highlighted Ruby code via right mouse click
Reported by
brian.ca...@gmail.com,
Aug 17 2016
|
||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS Highlighting Ruby code and trying to copy it via right click causes the browser to quit responding temporarily. Repeatedly clicking the right mouse button can trigger a hard lock. VERSION Chrome Version: 54.0.2824.0 dev-m (64-bit) Operating System: Windows 8.1 REPRODUCTION CASE While hunting for obfuscated code to fuzz Ruby with, I came across http://www.rubyinside.com/advent2006/4-ruby-obfuscation.html and while it looks ordinary, if you highlight the section entitled `Display Primes Less Than 1000` starting at $e="" and ending with eval $e. (Highlighting the parts that start with # nullify the issue for whatever reason we're going to conclude later on. After you highlight said text, right click to copy the text. You can't. Because it feels like Chrome is trying to actually eval $e. Repeatedly right clicking on the highlighted area will eventually hard lock the browser, requiring an `End Task`. Unable to replicate in IE or Firefox. FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION Type of crash: browser locks up Crash State: nothing available Client ID (if relevant):
,
Nov 24 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by jialiul@chromium.org
, Aug 17 2016