New issue
Advanced search Search tips

Issue 670476 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner: ----
Closed: Dec 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Impersonate URL displayed with mouse over using \u2028 \u2029

Reported by sec.repo...@gmail.com, Dec 1 2016

Issue description

VULNERABILITY DETAILS
When the user hovers over the a element,
if a specific character (\u2028 \u2029 ) is included in the link,
the line breaks there and the last line is displayed as the redirect destination.
It can also be reproduced if the character is percent encoded.

It has particular impact on services like github which displays markdown.

An attacker can use it for phishing because the redirect URL can be disguised.
If javascript protocol can be written, it is also possible to make xss harder to notice.

VERSION

Chrome Version: 54.0.2840.98 (64-bit)
Operating System: Mac OSX 10.11.6

REPRODUCTION CASE

* mardkown 
- [link text](https://github.com/[\u2028][\u2028]https://google.com)
- [link text](https://github.com/[\u2029][\u2029]https://google.com)
- [link text](https://github.com/%E2%80%A9%E2%80%A9https://google.com)
- [link text](https://github.com/%E2%80%A9%E2%80%A9https://google.com)

* html

<a href="https://github.com/[\u2028][\u2028]https://google.com">to google</a>
<a href="https://github.com/[\u2029][\u2029]https://google.com">to google</a>
<a href="https://github.com/%E2%80%A8%E2%80%A8https://google.com">to google</a>
<a href="https://github.com/%E2%80%A9%E2%80%A9https://google.com">to google</a>
 
Labels: -Restrict-View-SecurityTeam allpublic
Mergedinto: 444466
Status: Duplicate (was: Unconfirmed)
Thanks for the report.

The status bar is not a security indicator (http://www.chromium.org/Home/chromium-security/security-faq#TOC-Where-are-the-security-indicators-located-in-the-browser-window-), so this isn't a security vulnerability.

Sign in to add a comment