New issue
Advanced search Search tips

Issue 681520 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Chrome crashes after 500 thousand lines to a few million lines of malformed url strings

Reported by kingz...@gmail.com, Jan 16 2017

Issue description


VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

VERSION
Chrome Version: Version 55.0.2883.87 m stable
Operating System: Windows 10 Home 

REPRODUCTION CASE
When a user provides a malformed string, such as http://example.com//example.com/ and repeats it for 500 thousand characters or more the Chrome browser hangs and then Chrome shuts down completely killing all of it's processes and is unable to restore the previous tabs when it is restarted. 

This attack does not work if the website has cloudflare since they blocked it after we tested it too many times. Also, certain server configurations refuse to accept the malformed url, but after one million characters the site will either lead to the browser crashing or stop responding. If it stops responding and gives no error then a few more million lines should make the browser crash. We have reproduced this bug multiple times. We were going to try and gain control of memory, but your rules say to report early, instead of later.  If you have any questions or need help reproducing, since example.com may not reproduce the issue, we will be happy to assist and if we can find the area that has the flaw we will see if we can write a patch as well.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: Chrome, any tab, requires interaction with a server unless it freezes because there is too much text in the browser url address. 
Crash State: 
 
example-dot-com.txt
569 KB View Download
Labels: Needs-Feedback
I cannot reproduce this. I just got a connection cannot be reached error. Can you please provide another example or a crash backtrace?

Comment 2 by kingz...@gmail.com, Jan 17 2017

Yes I will. As noted some servers have proper protection against malformed urls that the browser can't parse, others do not. I will find a domain without proper protection to test on.

Comment 3 by aarya@google.com, Jan 17 2017

Status: WontFix (was: Unconfirmed)
There are several ways to hang a browser and this is not in security threat model.
https://www.chromium.org/Home/chromium-security/security-faq#TOC-Are-denial-of-service-issues-considered-security-bugs-

Comment 4 by kingz...@gmail.com, Jan 17 2017

I am aware of your denial of service rules and wouldn't be filing this if it didn't actually crash, not just a denial of service. If you aren't interested I'll stop reporting on this thread. 
Project Member

Comment 5 by sheriffbot@chromium.org, Apr 25 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment