New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 698601 link

Starred by 2 users

Issue metadata

Status: Archived
Owner: ----
Closed: Mar 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Possible exploit using the Install Extension dialog.

Reported by mbu...@gmail.com, Mar 5 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36

Steps to reproduce the problem:
1. A website may sometimes redirect to a malicious domain which contains the exploit.

What is the expected behavior?
The Website will make the browser go into fullscreen mode and prompt the user to install a malicious extension, over and over again.

What went wrong?
The extension install can only be aborted using the abort button, but the website can't be stopped from reopening it immediately. The malicious website may also display a message trying to look like the chrome browser itself.
The Extension Install dialog will also display on top of the fullscreen enabled message so users may not notice that they entered fullscreen mode.

Did this work before? N/A 

Chrome version: 56.0.2924.87  Channel: stable
OS Version: 10.0
Flash Version:

 
Labels: Needs-Triage-M56
Cc: krajshree@chromium.org
Components: Platform>Extensions
Labels: Needs-Feedback
mbust2@ - Thanks for filing the issue...!!

Could you please provide a sample URL to test this issue.

This will help us in triaging the issue further.

Thanks...!!
Project Member

Comment 3 by sheriffbot@chromium.org, Mar 6 2018

Status: Archived (was: Unconfirmed)
Issue has not been modified or commented on in the last 365 days, please re-open or file a new bug if this is still an issue.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment