New issue
Advanced search Search tips

Issue 676840 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 648117
Owner:
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Security



Sign in to add a comment

Document does not clear when navigating to data: URL

Reported by s.h.h.n....@gmail.com, Dec 23 2016

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.95 Safari/537.36

Steps to reproduce the problem:
1. Go to https://vuln.shhnjk.com/blank.html
2. Click Go.
3. Page is redirected but document remains same if we do window.stop() on redirected page. 

What is the expected behavior?
loads content on data URI

What went wrong?
Because unloading document it late, document is still same after redirection.

Did this work before? N/A 

Chrome version: 55.0.2883.95  Channel: stable
OS Version: OS X 10.11.6
Flash Version: Shockwave Flash 24.0 r0
 
Components: UI>Browser>Navigation
Status: Untriaged (was: Unconfirmed)
Summary: Document does not clear when navigating to data: URL (was: document does not get unload when redirecting to data: URL)
I believe the complaint is that the prior document's markup isn't visibly removed from the content area and the prompt dialog from the new data: markup is shown over that content. The omnibox does show the Data URI as expected. 

This seems unusual but of limited security impact because the Omnibox is the security surface.
Owner: creis@chromium.org
Status: Assigned (was: Untriaged)
Over to creis@, who is very familiar with navigation and can more appropriately decide on priority level/triage.

Comment 3 by kenrb@chromium.org, Dec 28 2016

Cc: creis@chromium.org
Mergedinto: 648117
Owner: kenrb@chromium.org
Status: Duplicate (was: Assigned)
I don't see anything new here. The original content goes blank after 4 seconds, which is by design when a new page has loaded but nothing has rendered on it. The old page *has* unloaded so it is not a real URL spoof, and we prevent its content from displaying underneath the new URL for an extended period of time. I see a problem that it doesn't clear if you do it a second time but I think this is the same as  bug 648117 .
Project Member

Comment 4 by sheriffbot@chromium.org, Jul 5 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment