New issue
Advanced search Search tips

Issue 665466 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Nov 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: chrome-devtools protocol allows to read the content of C:\ drive via watchExpression

Reported by chromium...@gmail.com, Nov 15 2016

Issue description

VERSION
Chrome Version: 54.0.2840.99 m
Operating System: Windows 7

REPRODUCTION CASE
1. Navigate to the link below.
2. Open Developer tools.
3. Switch to Sources panel >> Click on Watch >> observe.

To repro this on 56.0.2920.0 canary (64-bit) you should navigate to chrome-devtools://devtools/remote/serve_rev/@199588/devtools.html (before the step-1).



 
chrome-devtools.txt
1.4 KB View Download
Recording.mp4
293 KB View Download
Cc: dgozman@chromium.org
Components: Platform>DevTools
Similar to  Issue 653134  and  Issue 662859 

Comment 2 by mea...@chromium.org, Nov 18 2016

Cc: -dgozman@chromium.org
Owner: dgozman@chromium.org
Status: Assigned (was: Unconfirmed)
Not sure if I'm missing anything, but the code in the attachment throws a syntax error for me.

dgozman, could you please triage? Thanks.

Comment 3 by mea...@chromium.org, Nov 18 2016

Labels: OS-Chrome OS-Linux OS-Mac OS-Windows

Comment 4 by och...@chromium.org, Nov 29 2016

Labels: Security_Severity-Low Security_Impact-Stable
Unless I'm missing something here, it seems like you need to click the "Watch" button for this to work? Assigning low since that seems like an unlikely attack scenario.
Can't repro this after fixing  Issue 653134 .

Comment 6 by och...@chromium.org, Nov 29 2016

Status: WontFix (was: Assigned)
Ok, thanks for confirming!
Project Member

Comment 7 by sheriffbot@chromium.org, Mar 8 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment