Issue metadata
Sign in to add a comment
|
Security: A URL that will compromise Chrome
Reported by
john.arm...@gmail.com,
Mar 28 2017
|
||||||||||||||||||||||
Issue descriptionClicked on the following booby trapped URL. Simply opening the link was enough for it to remove all Chrome history, change the Chrome Home page and no doubt caused other damage but did not investigate further for fear of what other malicious actions the miscreant had in mind. https://www.baidu.com/link?url=nJV2sr0k6z2orx3UhEuATVv2lZj8XOSCXfD0ePY_NFe&id=john.armstrong Skype Version 57.0.2987.110 (64-bit)
,
Mar 28 2017
Just noticed an error in my original report. It should read Chrome Version 57.0.2987.110 (64-bit) NOT Skype Version...
,
Mar 28 2017
From Google's internal network the target URL simply redirects to http://aio-sim.ru/, which picks one of five different advertisements to show. No malicious behavior was seen.
,
Mar 28 2017
Many thanks for investigating that for me. As mentioned clicking link did originally clear my Chrome browser history and also reset my Home page to a page with ads (probably the same one you found but I since restored my VM from prior to that event so can't say for sure). Anyway thank you again for looking into this.
,
Mar 28 2017
I also tried, from other networks. It was probably triggering a bad ad which is gone now. If you see it again, grab a screenshot or otherwise record the origin of the page doing the harm. Thanks for the report.
,
Jul 5 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by john.arm...@gmail.com
, Mar 28 2017