New issue
Advanced search Search tips

Issue 686609 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: xss in chrome

Reported by venkates...@gmail.com, Jan 30 2017

Issue description

VULNERABILITY DETAILS
XSS: Chrome browser based vulnerability. Once after running the java script its able to give the alert box with gmail cookies if looged into gmail account.

i have reported it already but no update till now.
Report Details
-------------------
Email Subject: [8-8013000015913] XSS in None
Category: XSS
Product: None
Cid: 8-8013000015913 
date:	Fri, Jan 27, 2017 at 11:58 AM

VERSION
Chrome Version: Chrome Version 55.0.2883.87 m
Operating System: Windows 10 64 bit OS

REPRODUCTION CASE

1.Start your chrome
2.You can delete your old cookies(not necessary but to avoid confusions) 
3.Login with any google account
4.Open a new tab, in the address bar type "javascript:alert(document.cookie) or javascript:(document.domain)". 
5.It will display gmail cookie if you logged into gmail in other tab for document.cookie. For document.domain it will display www.google.com.
6.it all happens locally and any third party can steel cookie to hijack the account.

Attack scenario:
We can write a chrome extension to steel the cookies which leads session hijacking. And it may possible to get the key strokes, that's whatever we are typing in the page.

Regards,
Venkatesh
 
POC for XSS.docx
187 KB Download
Status: WontFix (was: Unconfirmed)
Thanks for the report. However, this is working as intended. Disabling javascript URLs would, for instance, break bookmarklets. See the security FAQ for more:

https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Does-entering-JavaScript:-URLs-in-the-URL-bar-or-running-script-in-the-developer-tools-mean-there-s-an-XSS-vulnerability-
I understand its intended but at what extent its right to show google cookies?
And if logged into number of web applications by default its bringing google cookie when you run the script.
Project Member

Comment 3 by sheriffbot@chromium.org, May 8 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment