New issue
Advanced search Search tips

Issue 685510 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Non deterministic Behavior, wrong SSL certificate to the wrong website

Reported by es.n...@gmail.com, Jan 26 2017

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://www.chromium.org/Home
/chromium-security/security-faq

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

VERSION
Chrome Version: 55.0.2883.95 Stable
Operating System: MacOS 10.12 

REPRODUCTION:
I tried to open a microsoft owned website. I got redirected back to Google with a Microsoft SSL certificate and Chrome thinking that the certificate corresponds.


 
Screen Shot 2017-01-25 at 23.56.42.png
201 KB View Download

Comment 1 by est...@chromium.org, Jan 26 2017

Labels: Team-Security-UX Needs-Feedback
Hi, thanks for the report. Are you able to reproduce this issue? If so, could you please attach a net-internals log as described in https://dev.chromium.org/for-testers/providing-network-details?

Comment 2 by wfh@chromium.org, Feb 2 2017

Status: WontFix (was: Unconfirmed)
Closing bug as the reporter has not replied with the required information, please feel free to re-open if you can supply a net-internals log.
Project Member

Comment 3 by sheriffbot@chromium.org, May 12 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment