New issue
Advanced search Search tips

Issue 732477 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jun 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security


Participants' hotlists:
Hotlist-1


Sign in to add a comment

Security: Chrome Browser hijacking issue from domains of Retailboy and Verosmedia

Reported by coolshi...@gmail.com, Jun 12 2017

Issue description

VULNERABILITY DETAILS
Some users when using browser Google Chrome: Version 59.0.3071.86 (Official Build) (64-bit) on the site mail.yahoo.com seems to get redirect to suspicious site of Retailboy and Verosmedia. This seems to start with Chrome browser and with no new local apps installed the user logged in session on Yahoo mail is redirected to above suspicious site without user consent. The redirection happens when user has multiple tabs and the focus is set to another tab or window leaving the yahoo mail session tab active.

VERSION
Chrome Version: [59.0.3071.86] + [stable]
Operating System: [Windows 7, version: 6.1, and service pack 1]

REPRODUCTION CASE
This seems to have popped up recently in internet and probably will spread massively as the vulnerability is open and still cannot be fixed by World's Strongest Anti malware app: Malwarebytes Antimalware. 
There has been serious discussions on this issue with respect to Chrome browser See the details here: 
https://forums.malwarebytes.com/topic/201955-incredibly-perplexing-browser-redirect-god-level-expert-needed/

The issue has also been reported to email provider yahoo but nothing of this sort have ever been caught. Probably the hacker(s) or Corporation(s) misusing this vulnerability in Chrome (alteast) are using the loophole of redirection straight from session signed in browser (probably with help of cookie or Javascript) without installing any addons or installers.

 
Labels: Needs-Feedback
Without more details (e.g. a network log), it's unlikely that there's anything that the Chrome can do to combat the malicious ads that are redirecting you to the unwanted sites.

Do you have any logs (e.g. https://dev.chromium.org/for-testers/providing-network-details)?

To eliminate any sort of local adware as a culprit, have you run the Chrome cleanup tool? https://www.google.com/chrome/cleanup-tool/index.html
I am an advanced user. I will run the above 2 steps tonight and will update this thread. Please leave this thread open
Project Member

Comment 3 by sheriffbot@chromium.org, Jun 12 2017

Cc: elawrence@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: Needs-Feedback
I have attached a net-export log as required. This time it didn't redirect me. See if this is helpful to you.
chrome-net-export-log.json
4.0 MB View Download
Project Member

Comment 6 by sheriffbot@chromium.org, Jun 14 2017

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 7 by est...@chromium.org, Jun 14 2017

Labels: Needs-Feedback
A net-internals log from when the redirect happens would be most useful.

Did you run the Chrome cleanup tool and did that fix the problem? If so, it would suggest that the problem is malware on your machine and not a vulnerability in Chrome.
I didn't run yet but ran Hitman Pro which cleaned some tracking cookies. So far no site redirection has happened but would keep an eye on it. What do you say?
Project Member

Comment 9 by sheriffbot@chromium.org, Jun 15 2017

Cc: est...@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "estark@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Status: WontFix (was: Unconfirmed)
Unfortunately there's not much we can do to help if you can't reproduce the problem. I recommend running the Chrome cleanup tool (https://www.google.com/chrome/cleanup-tool/index.html) to clean up your machine. If you see the problem again and can capture a net-internals logs, then we'll happily take a look at it to see if there's more we can do.
Project Member

Comment 11 by sheriffbot@chromium.org, Sep 22 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment