Deduction of mobile pre-paid balance while visiting website. No consent given.
Reported by
ralf....@gmail.com,
Jan 7 2017
|
||||
Issue descriptionSteps to reproduce the problem: 1. Incognito Tab with pop-ups blocked 2. Visit the https://www.indiansexstories.net/ website 3. Open same site links provided in the webpage. 4. As you open and navigate throught the website, popups will open. 5. Close the pop-ups even before they completely load. 6. Browse for 10 to 15 minutes. (Keep closing pop-ups) 7. Close browsing session 8. Check mobile pre-paid balance. 9. Repeat browsing What is the expected behavior? 1. Pop ups should not open as they are blocked in chrome settings. 2. Your mobile balance remains unaffected as you did not give consent for any service and only browsed free websites. What went wrong? 1. Pop ups were loading. 2. Balance deducted from mobile pre-paid balance. For each browsing session, the amount deducted varies and is reflective of your mobile balance. 3. Checking with mobile service provider intimated me that i had subscribed to third party content by providing consent on clicking yes in pop-ups and to avoid it in future, activate pop-up blocking. (which was already activated in this case and no consent provided.) Did this work before? N/A Chrome version: 55.0.2883.91 Channel: stable OS Version: 6.0.1 Flash Version: Possibile security flaws. Since amount deducted is reflective of mobile pre-paid balance, any possibilty of gaining mobile details through metadata while browsing on chrome.
,
Jan 17 2017
This is not a security vulnerability, removing tags.
,
Nov 24 2017
@raif.mak -- Thank You for the report. Could you please upgrade to latest Chrome# 62.0.3202.84 and provide the latest behavior, if yes provide us with the screen cast which would help us in triaging the issue further. Thanks in Advance.
,
Mar 8 2018
***Bulk Edit*** There is no updates in the past few months, closing now. Feel free to reopen if needed. |
||||
►
Sign in to add a comment |
||||
Comment 1 by elawrence@chromium.org
, Jan 9 2017