New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 723956 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 703750
Owner:
Closed: May 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 2
Type: Bug-Security



Sign in to add a comment

Security: Whole-script confusable domain label spoofing

Reported by chromium...@gmail.com, May 18 2017

Issue description


VERSION
Chrome Version: OS X 
Operating System: 60.0.3102.0 canary

fåcebook.com

In this issue I used A with a ring.
 
Cc: js...@chromium.org
Components: UI>Security>UrlFormatting
Interestingly, fåcebook.com actually resolves, but it immediately redirects elsewhere.

Comment 2 by wfh@chromium.org, May 18 2017

Cc: -js...@chromium.org
Components: UI>Browser>Omnibox Blink>JavaScript>Internationalization
Labels: Security_Severity-Medium Security_Impact-Stable Team-Security-UX OS-All Pri-2
Owner: js...@chromium.org
Status: Assigned (was: Unconfirmed)
jshin@chromium.org please take a look at this. Thanks.

Comment 3 by jochen@chromium.org, May 18 2017

Components: -Blink>JavaScript>Internationalization
Not v8 specific

Comment 4 by mgiuca@chromium.org, May 19 2017

Mergedinto: 703750
Status: Duplicate (was: Assigned)
This is the same general issue as  Issue 703750  -- using a single Latin character that looks similar to an ASCII character.

The A WITH RING is far easier to notice than many of the other more subtle ones. We don't need more reports like this. They are all the same issue and will have the same fix (if any). The Unicode Consortium supplies a list of confusables so we do not need individual bug reports of each look-alike character.

We can't just blacklist these characters, since they are legitimate characters in their own right. We may need to work out how to avoid spoofs of popular sites. This is being discussed in  Issue 703750 .
Project Member

Comment 5 by sheriffbot@chromium.org, Aug 25 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment