Issue metadata
Sign in to add a comment
|
Security: Chrome Flash Player disabled bypass
Reported by
ma7h1a...@gmail.com,
May 16 2017
|
||||||||||||||||||||||
Issue descriptionVERSION Chrome Version:58.0.3029.110 stable Operating System: Windows 10 enterprise In the last issue i did not make a clearly description of this security bug So that make some mistakes I modify the description and add the source code of Designed-Flash-File VULNERABILITY DETAILS Chrome version 58 disabled flash execution at most time Flash could not execute without user's permission But,with this Issue,Flash Player is being enabled without any notifications to the user. Once the flash player is enabled,Hacker could use this bug and a Designed-Flash-File to perform an Cross-Domain-CSRF With further vulnerability from Flash side, it might leak user's private information and even potentially allow remote execution REPRODUCTION CASE new.html is used to repreduce this Security bug After about 300 times click ,flash player is enabled without user's permission The result.png shows the flash player is enabled And evil.cs is the source code of Designed-Flash-File Load the swf,and use FlashVars to send the param Which used to perform an Information-Stolen or CSRF attack
,
May 16 2017
,
Nov 7 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, May 16 2017