New issue
Advanced search Search tips

Issue 739753 link

Starred by 4 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Malicious Chrome tab crashing results in disabled antivirus

Reported by j...@henderson3.net, Jul 6 2017

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://www.chromium.org/Home
/chromium-security/security-faq

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Malicious popup is able to crash Chrome tab and disable Windows Defender.

VERSION
Chrome Version: 59.0.3071.115 + stable
Operating System: Windows 10 version 1607

REPRODUCTION CASE
A popup at the URL http://digiboko.online/am.php?pubid=76535_85279&clickid=FPMYxTD4Yes&country=at&v=1559206473 was able to force Chrome into full screen mode, and repeated confirm() javascript dialog boxes made it impossible to exit (even unable to check the "prevent page from create additional dialogs" checkbox). The page attempts to install a malicious extension from the Chrome store (already reported). Eventually, the tab crashes along with AdBlock extension, and somehow Windows Defender was able to be disabled. Still reviewing if any further damage has been done. The HTML output of this malicious page is attached.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: tab
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

 
HTML - 2017-07-06_17.22.07.txt
3.8 KB View Download
Labels: Needs-Feedback
It's definitely a bad site, submitted for blocking.

- It abuses full-screen
- It abuses onbeforeunload
- It uses fake dialogs (images that pretend to be Chrome UI, including fake extension installs and fake "block dialogs" checkboxes)
- It uses cursor-jacking so it's not clear where the user is actually clicking ( Issue 640227 )
- It puts additional pages in the history stack so clicking "Back" and "Leave Site" doesn't help

I'm not able to reproduce any sort of crash in interacting with this scenario. Can you please visit chrome://crashes and get the ServerID value for your crash report so we can have a look?

I'm not able to reproduce any badness with Windows Defender (nor is there any reasonable explanation for how that would happen).

Comment 2 by raymes@chromium.org, Jul 14 2017

Status: WontFix (was: Unconfirmed)
elawrence: this site still seems to be working. I escalated internally for review. I think all of the issues themselves are known issues. The cursor issue seems particularly nasty here though..

Given that we don't have a crash report I'm closing this for now.
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 22 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment