New issue
Advanced search Search tips

Issue 705922 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: A URL that will compromise Chrome

Reported by john.arm...@gmail.com, Mar 28 2017

Issue description

Clicked on the following booby trapped URL.  Simply opening the link was enough for it to remove all Chrome history, change the Chrome Home page and no doubt caused other damage but did not investigate further for fear of what other malicious actions the miscreant had in mind.

https://www.baidu.com/link?url=nJV2sr0k6z2orx3UhEuATVv2lZj8XOSCXfD0ePY_NFe&id=john.armstrong


Skype Version 57.0.2987.110 (64-bit)

 
The full URL of the malicious URL including personal information was submitted with this report in case it is all required in order to trigger the Chrome security issue.

However can I ask that the personal information is removed from the URL if the report is going to be exposed beyond the initial group of users with Security Team permission.

Also I would be grateful if you are able to establish what information the malicious URL is able to extract from Chrome - i.e. could it have read my passwords that Chrome stores for me?
Just noticed an error in my original report.  It should read Chrome Version 57.0.2987.110 (64-bit) NOT Skype Version...


Components: Services>Safebrowsing
Summary: Security: A URL that will compromise Chrome (was: Security: A URL that will compromize Chrome)
From Google's internal network the target URL simply redirects to http://aio-sim.ru/, which picks one of five different advertisements to show. No malicious behavior was seen.
Many thanks for investigating that for me.  
As mentioned clicking link did originally clear my Chrome browser history and also reset my Home page to a page with ads (probably the same one you found but I since restored my VM from prior to that event so can't say for sure).
Anyway thank you again for looking into this.
Status: WontFix (was: Unconfirmed)
I also tried, from other networks.  It was probably triggering a bad ad which is gone now.

If you see it again, grab a screenshot or otherwise record the origin of the page doing the harm.  Thanks for the report.
Project Member

Comment 6 by sheriffbot@chromium.org, Jul 5 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment