New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 671248 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Last visit > 30 days ago
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: ----
Type: Bug



Sign in to add a comment

Download protection bypass

Reported by osmanstp...@gmail.com, Dec 5 2016

Issue description

This template is ONLY for reporting Download Protection Bypass bugs within
Chrome and is not for requesting a review of sites or binaries identified
as malicious.

VERSION
Google Chrome	54.0.2840.99 (Official Build) m (32-bit)
Operating System: Windows 10

REPRODUCTION CASE
Downloader extension allows the malware test file (malware example, UwS example) 
to be downloaded. Without the extension--Google Chrome automatically blocks the file saying it is harmful, but with the extension--the file simply goes straight to downloads folder where a user can easily run it. The extension does give the person an option to keep or discard.  Hopefully this qualifies for the download bypass reward because the 2 sample Malicious test .exe's both ended up in downloads folder. An extension can be made where it will auto download it and won't prompt anything.


 
Capture.PNG
90.0 KB View Download
Capture2.PNG
21.5 KB View Download
Thanks for the report.  Can you provide a link to the specific extension you used?

Comment 3 by ajha@chromium.org, Dec 6 2016

Labels: M-54 OS-Windows
Owner: jialiul@chromium.org
Status: WontFix (was: Unconfirmed)
WAI
Based on your screenshot Capture.PNG, the confirm download dialog did show up with appropriate warning text "content.exe is malicious, and chrome has blocked it." 

Comment 6 by vakh@chromium.org, Mar 10 2017

Labels: -Restrict-View-Google Restrict-View-SecurityTeam
For all Download Protection VRP bugs: removing label Restrict-View-Google and adding Restrict-View-SecurityTeam instead.
Project Member

Comment 7 by sheriffbot@chromium.org, Mar 30 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment