New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 662827 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug

Blocked on:
issue 718281



Sign in to add a comment

Security: DoS possible in chrome browser

Reported by pvishal...@gmail.com, Nov 7 2016

Issue description

Hi chrome team,
VULNERABILITY DETAILS
Basically I have found a denial of service attack on Chrome browser in window platform.In this bug when we open the html file or visiting (www.tiks.host-ed.me) then click on pop up dos.html ,(which contains a recurring pop up code),the Pop up freezes the entire browser window except for minimize button and on maximizing it hangs, we can't close any tabs neither using (Ctrl+w) to close current tab that is causing recursion.And in safari browser Pop up's come after some time delays that allows user to stop the running process by clicking on (X) in URL.

VERSION
Chrome Version: Latest version
Operating System: Windows 7 (x64)
REPRODUCTION CASE
i have created a HTML page.just open in chrome browser.

please let me know if you want more info or PoC.
 
pop_up_dos.html
185 bytes View Download
Cc: a...@chromium.org
Components: UI>Browser>PopupBlocker
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Pri-2 Type-Bug
Thanks for the report.  Avi -- Is this a new variety of popup DoS?

Marking it as non-security.

Does doesn't repro on Mac canary -- I can stop it from showing more alerts, and then close the window.

Can you please clarify what the DoS here is?

Assuming that your popup blocker settings aren't modified (i.e. you didn't manually disable the popup blocker), the attached demo doesn't open a single popup, and the alert() dialogs can be dismissed by checking the "prevent this page from showing further dialogs" setting in the alert itself
Cc: tkonch...@chromium.org
Labels: Needs-Feedback
 pvishal327@, Could you please respond as per comment #2
Blockedon: 718281
jochen: popup window aside, the "prevent this page..." checkbox does not appear in the repeated alert dialog on Windows :-(

Comment 5 by a...@chromium.org, May 4 2017

Status: WontFix (was: Unconfirmed)
I'm closing this, as this has gotten no feedback.

Michael, the "prevent this page" checkbox was deliberately removed. If a tab is harassing you with alerts, close it.

Sign in to add a comment