New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 719143 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 683314
Owner: ----
Closed: May 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug-Security



Sign in to add a comment

Adress bar spoofing on chrome android

Reported by narendra...@gmail.com, May 6 2017

Issue description

Steps to reproduce the problem:
It is same issue as https://bugs.chromium.org/p/chromium/issues/detail?id=683314

I know  this is same as that issue but this can spoof url bar on chrome android browser

1. Just visit https://www.xn--80ak6aa92e.com/ 
2. You will see spoofed content under www.apple.com

What is the expected behavior?
Content should be provided as in url bar "https://www.xn--80ak6aa92e.com/" not as "www.apple.com"

What went wrong?
Punycode makes it possible to register domains with foreign characters. It works by converting individual domain label to an alternative format using only ASCII characters. For example, the domain "xn--s7y.co" is equivalent to "短.co". 

Did this work before? N/A 

Chrome version: <Copy from: 'about:version'>  Channel: n/a
OS Version: 57.0.2987.132
Flash Version:
 
Screenshot_2017-05-06-11-16-31.png
111 KB View Download
Labels: Needs-Feedback
It looks like the fix for  bug 683314  made it to 58, but not 57. Can you please update Chrome and see if it still reproduces?

Comment 2 by aarya@google.com, May 9 2017

Mergedinto: 683314
Status: Duplicate (was: Unconfirmed)
Can't reproduce it anymore on 58, closing.

Comment 3 by raymes@chromium.org, May 15 2017

Cc: mgiuca@chromium.org
Project Member

Comment 4 by sheriffbot@chromium.org, Aug 16 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment