Issue metadata
Sign in to add a comment
|
Security: Address Bar Spoofing
Reported by
rayyan...@gmail.com,
Apr 7 2017
|
||||||||||||||||||||||
Issue descriptionChrome Version: [56] + [beta] Operating System: [Android 4.1.2] Imact and Risk: the URL bar is the only reliable security indicator in browsers and if the only reliable security indicator could be controlled by an attacker it could carry adverse affects, For instance potentially tricking users into supplying sensitive information to a malicious website due to the fact that it could easily lead the users to believe that they are visiting is legitimate website as the address bar points to the correct website. Reproduction Instructions/Proof of Concept: 1) Post the following link in the status bar: 127.0.0.1/ا/http://attack.com 2) You would notice that the URL has been flipped from Right to left and the status bar dispays http://attack.com/ا/127.0.0.1 while it displays the content from the IP address.
,
Apr 7 2017
This appears to be the same repro as Issue 708981 ?
,
Apr 7 2017
Yes, But in iOS - The bug is fixed but not completely fixed (watch the video provided to make this confusion clear).. But here, the bug is working fully as illustrated. Plus, I've written Andriod 4.1.2 ( I was testing on it) but it obviously works on all android versions.
,
Apr 9 2017
Hi, Make the OS Android 6.0 - As it was again tested in it, therefore, it works there! thanks!
,
Apr 9 2017
+mgiuca to dedupe.
,
Apr 9 2017
,
Apr 10 2017
Hi, Isn't the Security Severity is high/medium even after describing the impact and risk?
,
Apr 10 2017
,
Apr 12 2017
This is exactly the same as the issue you reported in Issue 709417 . You don't need to report the issue separately on each channel of Chrome.
,
Aug 4 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by rayyan...@gmail.com
, Apr 7 201711.8 KB
11.8 KB View Download