Issue metadata
Sign in to add a comment
|
'About:blank' Address Bar URI Spoofing
Reported by
vladimir...@gmail.com,
May 5 2017
|
||||||||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS 'About:blank' Address Bar URI Spoofing allows an attacker to show dangerous content on the page with URL 'About:blank'. User can interact with the fake 'about:blank' page. VERSION Chrome Version: 57.0.2987.133 stable Operating System: Mac OS X(latest) Exploit works in Google Chrome Canary 60.0.3090.0 and Chromium-based browsers for Mac OS X too. REPRODUCTION CASE Open attached to this report HTML file in Google Chrome.
,
May 5 2017
Sorry, maybe reproduction is not clear. Alert isn't a part of the repro. It can be excluded from the code. URL of this page (e.g. evildomain.com) changes to 'about:blank' after this page was loaded. So page loaded from evildomain.com will be displayed with url 'about:blank'. HTML file without alert attached:
,
May 5 2017
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 5 2017
Example(screenshot): The website was loaded from localhost, but displayed URL changed to 'about:blank'. Behavior of other browsers: - Mozilla Firefox throws error about malformed URL.
,
May 5 2017
This looks like bug 571784. |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, May 5 2017Labels: Needs-Feedback