New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 643173 link

Starred by 9 users

Issue metadata

Status: Fixed
Merged: issue 642838
Owner:
Closed: Sep 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Windows , Mac
Pri: 1
Type: Bug-Security



Sign in to add a comment

Wrong security state when redirecting to HTTP

Reported by jleedev@gmail.com, Sep 1 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2845.0 Safari/537.36

Steps to reproduce the problem:
Visit https://www.google.com/#newwindow=1&q=%22http.badssl.com%22
 and click on the first result.

What is the expected behavior?

What went wrong?
Lock icon is shown. Devtools Security Panel says this page is secure.

Did this work before? Yes 

Chrome version: 55.0.2845.0  Channel: canary
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: 

Correct behavior in 414731
Bad behavior in 415292
 
Labels: -Type-Bug -Pri-2 Pri-1 Type-Bug-Security
Status: Available (was: Unconfirmed)
Regression on Windows and OS X. Looks okay in 55.0.2844, bad in 2845 and 2846, so this is a very recent regression.
Cc: jam@chromium.org
Components: -UI Security>UX
Suspect this'll be fixed by https://codereview.chromium.org/2299843002/?
(I can't reproduce on 55.0.2846.0 on OS X though.)

Comment 5 by vakh@chromium.org, Sep 1 2016

Labels: OS-Mac
Mergedinto: 642838
Status: Duplicate (was: Available)
I can repro it on: 55.0.2845.0 canary (64-bit) on OSX.
Seems like a duplicate of  Issue 642838  (SSL state not updated on restoring tab).

Comment 6 by vakh@chromium.org, Sep 2 2016

Cc: -jam@chromium.org
Owner: jam@chromium.org
Status: Assigned (was: Duplicate)
re-opening since the fix for  issue 642838  did not fix this.

jam@ -- do you want to take on this one also?

Comment 7 by vakh@chromium.org, Sep 2 2016

Labels: Security_Impact-Head

Comment 8 by jam@chromium.org, Sep 2 2016

Status: Started (was: Assigned)
doh, looking. I didn't test this case.

Comment 9 by vakh@chromium.org, Sep 3 2016

 Issue 643905  has been merged into this issue.

Comment 10 by aarya@google.com, Sep 3 2016

Cc: elawrence@chromium.org
Labels: Restrict-View-SecurityTeam
When you add Type-Bug-Security, make sure to add Restrict-View-SecurityTeam.

Comment 11 by vakh@chromium.org, Sep 4 2016

 Issue 643963  has been merged into this issue.

Comment 12 by vakh@chromium.org, Sep 6 2016

 Issue 644120  has been merged into this issue.
Labels: ConnectionInfo

Comment 14 by jam@chromium.org, Sep 7 2016

Status: Fixed (was: Started)

Comment 16 by jam@chromium.org, Sep 7 2016

Status: Fixed (was: Started)
Project Member

Comment 17 by sheriffbot@chromium.org, Sep 8 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
 Issue 645434  has been merged into this issue.
Cc: spqc...@chromium.org
 Issue 645485  has been merged into this issue.
Components: -Security>UX
Labels: Team-Security-UX
Security>UX component is deprecated in favor of the Team-Security-UX label
Project Member

Comment 21 by sheriffbot@chromium.org, Dec 15 2016

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: reward-topanel
Labels: Security_Severity-High
Reproduced with 55.0.2845.0

(used example.com to confirm I could interact with the page, follow links etc, which I could)
Screen Shot 2017-11-20 at 13.56.07.png
224 KB View Download
Labels: -reward-topanel reward-unpaid reward-1000
*** Boilerplate reminders! ***
Please do NOT publicly disclose details until a fix has been released to all our users. Early public disclosure may cancel the provisional reward. Also, please be considerate about disclosure when the bug affects a core library that may be used by other products. Please do NOT share this information with third parties who are not directly involved in fixing the bug. Doing so may cancel the provisional reward. Please be honest if you have already disclosed anything publicly or to third parties. Lastly, we understand that some of you are not interested in money. We offer the option to donate your reward to an eligible charity. If you prefer this option, let us know and we will also match your donation - subject to our discretion. Any rewards that are unclaimed after 12 months will be donated to a charity of our choosing.
*********************************
Cc: awhalley@chromium.org
Labels: -Reward-1000 -Security_Severity-High Security_Severity-Medium reward-2000
Hi jleedev@ - the Chrome VRP (after a rather long delay, sorry about that!) looked at this issue and decided to reward $2,000!  A member of our finance team will be in touch to arrange details.  Also, how would you like to be credited?
Labels: -reward-unpaid reward-inprocess

Comment 27 by jleedev@gmail.com, Dec 1 2017

Yay! Josh Lee.

Sign in to add a comment