New issue
Advanced search Search tips

Issue 689343 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 6773
Owner: ----
Closed: Feb 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Bug



Sign in to add a comment

Chrome self.close()

Reported by mishra.d...@gmail.com, Feb 7 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0

Steps to reproduce the problem:
The chrome browser fails to sanitize a check when self.close()
function is called in number of dynamically generated events. The
function is called in a suppressed manner and kills the parent window
directly by default.

What is the expected behavior?
The parent tab or browser should not get close.
This security issue is a result of design flaw in the browser.Scripts must not close windows that were not opened by script,if script specific code is designed.There must be a parent window confirmation check prior to close of window.

Other Browser:
IE : Gives a popup 
Mozilla: Doesn't works. 

What went wrong?
Fails to Sanitize self.close() or similar
<html><body>
<script>
self.close();
</script>
</body></html>

Did this work before? N/A 

Chrome version: 55.0.2883.87 (Official Build) m (64-bit)  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: Shockwave Flash 24.0 r0

 
close.html
67 bytes View Download
Components: Blink>DOM
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Likely a variant/duplicate of Issue 6773.

Chrome does not track denial of service issues as security vulnerabilities.
https://www.chromium.org/Home/chromium-security/security-faq#TOC-Are-denial-of-service-issues-considered-security-bugs-
Labels: Needs-Milestone
Labels: M-58 OS-Linux OS-Mac
Status: Untriaged (was: Unconfirmed)
Able to reproduce the issue on Windows 7, Ubuntu 14.04 using stable#56.0.2924.87 , Canary#58.0.3011.0  & reported version-55.0.2883.87 as per the given html file.On Mac 10.12.2-chrome browser is getting closed when we ran .html file.
No close confirmation popup box displayed on all the above mentioned versions & same the issue observed from M30 builds onwards.Hence marking this issue as 'Untriaged'.
Please find the attached screencast for reference.
Thanks.
689343.mp4
450 KB View Download
Labels: -Needs-Milestone
Mergedinto: 6773
Status: Duplicate (was: Untriaged)
Indeed I think this is a dup.

Sign in to add a comment