New issue
Advanced search Search tips

Issue 722941 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 722733
Owner: ----
Closed: May 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Chrome Flash Player disabled bypass

Reported by ma7h1a...@gmail.com, May 16 2017

Issue description

VERSION
Chrome Version:58.0.3029.110 stable
Operating System: Windows 10 enterprise

In the last issue i did not make a clearly description of this security bug
So that make some mistakes
I modify the description and add the source code of Designed-Flash-File

VULNERABILITY DETAILS
Chrome version 58 disabled flash execution at most time
Flash could not execute without user's permission
But,with this Issue,Flash Player is being enabled without any notifications to the user.
Once the flash player is enabled,Hacker could use this bug and a Designed-Flash-File to perform an Cross-Domain-CSRF
With further vulnerability from Flash side, it might leak user's private information and even potentially allow remote execution

REPRODUCTION CASE

new.html is used to repreduce this Security bug
After about 300 times click ,flash player is enabled without user's permission
The result.png shows the flash player is enabled
And evil.cs is the source code of Designed-Flash-File
Load the swf,and use FlashVars to send the param
Which used to perform an Information-Stolen or CSRF attack
 
 
evil.as
1.0 KB View Download
result.png
20.3 KB View Download
new.html
825 bytes View Download
index.html
14 bytes View Download
x.html
109 bytes View Download
Components: Internals>Plugins>Flash
As far as I can tell, this is  Issue 722733 . Rather than opening a new bug, you should update your remarks on the existing issue.

Comment 2 by wfh@chromium.org, May 16 2017

Mergedinto: 722733
Status: Duplicate (was: Unconfirmed)
Project Member

Comment 3 by sheriffbot@chromium.org, Nov 7 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment