New issue
Advanced search Search tips

Issue 683880 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Google Search results page shows Unicode content outside of result boxes

Reported by ivancer...@gmail.com, Jan 23 2017

Issue description

I'm not really sure the category under which this bug should be placed but I'm going to keep it as simple and straightforward as possible. (It could be a security issue, in my opinion, since someone was able to "hijack" the google search results page)

If you search for "correo electronico", text starts popping out of a website description section across the whole website and I think that this issue should be fixed ASAP.

I've tried it on multiple computers and the issue persists (although it does not appear on the mobile version).

Here is a screenshot of that issue: http://prntscr.com/dz7v7y

Also, I'd like to take this chance, since I'm already contacting Google, to see if there is any possibility of engaging into a remote work position (can be volunteering as well. I'm a 20 year old IT student from Croatia with front-end development experience but at this moment I'm working as an intern (production management) for a global Digital Agency. Anyhow, I'd appreciate a response regarding this section. I'm able to provide you with all the material needed (CV, portfolio, motivation etcetera).

Kind regards, looking forward to see this issue fixed! 

 
Components: Blink>Layout
Status: Untriaged (was: Unconfirmed)
Summary: Google Search results page shows Unicode content outside of result boxes (was: Text popping out of sections in a specific search term)
The page leading to this is http://www.correoiniciosesion.com/gmail-correo-electronico/?, the first link on which leads to a page blocked by SafeBrowsing, so this Unicode does appear to be an attempt to increase the visibility of the attack site.

That said, I'm not entirely convinced that this is a browser security vulnerability.

On Mac (without the target font) the search entry result item is just hundreds of pixels high, but it is constrained within its box.
Screen Shot 2017-01-23 at 7.58.02 AM.png
183 KB View Download

Comment 2 by est...@chromium.org, Jan 24 2017

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Untriaged)
Thanks for the report. As mentioned in Comment 1, this looks like a possible issue with Google search, not a security vulnerability in Chrome. https://www.google.com/appserve/security-bugs/m2/new is probably the right place to report it.

Sign in to add a comment