Issue metadata
Sign in to add a comment
|
Security: Infinite redirects with long URL can cause browser crash
Reported by
pig.wi...@gmail.com,
Jan 6 2017
|
||||||||||||||||||||||
Issue description
VULNERABILITY DETAILS
Chrome browser crash in android platform through --->
<html>
<a href="data:text/html;charset=utf-8,<script>window.location+='?'+window.location.toString().split('');</script>">ddos</a>
</html>
similar to report -----> https://bugs.chromium.org/p/chromium/issues/detail?id=33952
VERSION
Chrome Version: [55.0.2883.91] + [stable]
Operating System: [android 5.1.1]
REPRODUCTION CASE
Go to www.tiks.host-ed.me then click on spoof.html then click on the link(ddos) and browser crashes.
Type of crash: [browser]
Crash State: "Unfortunately,Chrome has stopped"
,
Jan 10 2017
yes i can confirm exception occurring in 57.0.2954.0
,
Jan 10 2017
,
Jan 13 2017
any updates?
,
Jan 19 2017
This is already fixed in M-56 (going stable at the end of January) by Ted. The exception in logcat is just a printed FYI -- we are unable to call system APIs with such a long URL. The exception is caught and handled.
,
Apr 28 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by rsesek@chromium.org
, Jan 9 2017Components: UI>Browser>Navigation
Labels: Security_Severity-Low M-57 Security_Impact-Stable OS-Android
Owner: mariakho...@chromium.org
Status: Assigned (was: Unconfirmed)