New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 717465 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Oct 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Thumbnails on desktop NTP do not match title & favicon

Reported by sharif.y...@beximtex.com, May 2 2017

Issue description

in the chrome thumbnail, it shows both facebook and gmail thumbnails.
So user may get easily confused.

Please see the attachment

Please fix it.
 
123.PNG
232 KB View Download
Components: UI>Browser>NewTabPage
It's not clear that there's really a security impact here, but it is definitely odd to see a Facebook thumbnail in the Gmail preview area.
Perhaps a variant of  Issue 695779 ?
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
-security flags.
Labels: OS-Windows Pri-2
Cc: treib@chromium.org mastiz@chromium.org
+treib, mastiz
Labels: Needs-Milestone

Comment 7 by mastiz@chromium.org, May 12 2017

This bug reminds me of the recent Issue 715149, which I however think is unrelated.

Some questions:
1. The attached screenshot displays some arabic text: I suppose this is WAI and unrelated to this bug report?

2. Does the thumbnail get fixed if you click on it? If that's the case, and since you're signed in, that'd point to Kodachrome as suspect, which is the server-side infrastructure to provide thumbnails when no local one is available.


Comment 8 Deleted

Comment 9 by mastiz@chromium.org, May 12 2017

The questions above are for the reporter, sharif.yellow@beximtex.com, thanks.
1. I dont know all about this. I am not technical person.
2. No it does not. its been looking same more than a month.

Comment 11 by ajha@chromium.org, May 25 2017

Labels: TE-NeedsTriageHelp
Now, I don't see any error.

All thumbnail are showing correctly.
Status: WontFix (was: Unconfirmed)
This must have been a transient issue with our server-side infrastructure to provide thumbnails. Will close the bug since it's not reproducible anymore, thanks for reporting. 
Excellent!

It's great that you found the solution.

Am I entitled to get the reward now?
May I expect any reply?
Sorry for the silence. I have myself limited knowledge about reward programs, please check https://www.google.com/about/appsecurity/chrome-rewards/
Thank you so much for your prompt reply.

Well, I have also not very familiar with the reward program.

However, as you label this issue as a security issue(see first email: Labels:
-Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug )
& since it is high quality report e.g. " a transient issue with our
server-side infrastructure to provide thumbnails", so I believe it falls
under the below category


*-Renderer Remote Code Execution - High-quality report with*
*functional exploit *

Here is the screen shot:

[image: Inline image 1]


Being the best company in the world, I believe, Google will appreciate my
effort.
Thanks for the kind words and sorry for not being able to help you with this stage. I can only refer you to the link in comment #16.
Hello sharif.yellow@ - I'm afraid this doesn't qualify for a reward as while there might be some confusion, there is no security risk to the user in this case.
Hello awhalley@,

Thanks for clarifying that it's not a security issue.

However, you have mentioned that it's a server side issue *@ Comment #13 *

Let me quote you

*"This must have been a transient issue with our server-side infrastructure
to provide thumbnails. *
*Will close the bug since it's not reproducible anymore, thanks for
reporting."*


If it's true, then it could fall under "Google Vulnerability Reward Program
(VRP) ".
Link: https://www.google.com/about/appsecurity/reward-program/index.html

In that case, it could qualify for the program.

[image: Inline image 1]

Please advise me.
Owner: treib@chromium.org
Status: Assigned (was: WontFix)
Summary: Thumbnails on desktop NTP do not match title & favicon (was: Security: in the chrome thumbnail, it shows both facebook and gmail thumbnails.)
Two comments:

1. wrt the conclusion in c#13: I don't think this is related to Kodachrome. The thumbnails show Facebook while being logged in. Kodachrome doesn't have access to client side cookies. So it's impossible that it produced this screenshot. I rather suspect some client side problem. @treib: Didn't you recently work on the thumbnail generation part?

2. wrt the discussion about the bug bounty: The program mentioned in c#20 IMHO is only applicable if you can actually demonstrate a working attack. The attack must put "confidentiality or integrity of user data" at risk. This is not the case here since Chrome 'just' shows the wrong thumbnail. This is undoubtedly very confusing and definitively should be fixed, but it doesn't put your data at risk (at least as far as I can tell). Therefore I think this doesn't apply here.

But let me point out once more that your report is very much appreciated! Keep on reporting issues - this is very helpful for us!
All my recent changes landed after this report, and none of them have even made it to Stable yet.

The screenshot in the report is from a non-standard NTP, probably overridden by an extension. sharif.yellow@, can you try uninstalling or disabling that extension, and checking if the standard NTP also has this problem? It's possible that the problem is in that extension rather than in Chrome itself.

Comment 23 by treib@chromium.org, Aug 21 2017

Labels: Needs-Feedback
Owner: ----
Status: Unconfirmed (was: Assigned)
Setting back to Unconfirmed while we wait for confirmation if this also happens on the standard NTP, as opposed to some extension-provided one which we don't control.
it's happening to other devices also.

I could help you guys but it requires time.

Are you sure the issue does not fall in any reward category?
Project Member

Comment 26 by sheriffbot@chromium.org, Oct 11 2017

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "treib@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 27 by treib@chromium.org, Oct 11 2017

Sorry, as far as I know there are rewards only for security issues.
Please remove my email from the CC.

Comment 29 by treib@chromium.org, Oct 12 2017

Status: WontFix (was: Unconfirmed)
Closing as not reproducible then. Presumably this was related to the extension-overridden NTP.

Sign in to add a comment