Issue metadata
Sign in to add a comment
|
Security: Address bar spoofing via window.open()
Reported by
chromium...@gmail.com,
May 8 2017
|
||||||||||||||||||||||||
Issue descriptionVERSION Chrome Version: 60.0.3091.0 canary Operating System: Windows 7 REPRODUCTION CASE 1. Visit http://jsbin.com/dogakinegi 2. Click on 'Click here' button 3. Observe
,
May 8 2017
Minimized testcase:
w = window.open('https://www.google.com/csi');
w.document.write('This is fake!');
,
May 8 2017
This is at least severity medium, and possibly high depending on whether we consider the spoof compelling (e.g. no lock, etc).
,
May 8 2017
Trying the minimized case locally (as in comment #3) seems to show "about:blank" in the omnibox, as expected. This may be fallout from PlzNavigate or OOPIF experiments?
,
May 8 2017
Initial attempt to bisect yields no obvious culprits: You are probably looking for a change made after 465478 (known good), but no later than 465485 (first known bad). CHANGELOG URL: https://chromium.googlesource.com/chromium/src/+log/b1acf5794d7c39d91a104571216213ab5841b93b..b8d842d9a8a6d837901ce9ef4629c6ebdaef5694
,
May 8 2017
Hmm. The internal bisect script points to a V8 roll which seems... surprising. You are probably looking for a change made after 465483 (known good), but no later than 465484 (first known bad). https://chromium.googlesource.com/chromium/src/+log/0f47d06919be1dfd8a307f2dca899612dcb68f9a..8267f48654eb20e9d6453b53f2da310953d244f1
,
May 8 2017
https://chromium.googlesource.com/v8/v8/+/cd76322817760cd1c1d7538f51f1907df7b6cde3 which was only one of two checkins in that v8 roll looks a bit suspicious.
,
May 8 2017
I don't repro this locally, still looks bad. Also, I can spoof with e.g:
w = window.open('http://xn----zmcjivgk7jmdb3e.xn--mgberp4a5d4ar/');
w.document.write('This is fake!');
And also:
w = window.open('https://gmail.com:91');
w.document.write('This is fake!');
,
May 8 2017
,
Aug 19 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by chromium...@gmail.com
, May 8 2017