New issue
Advanced search Search tips

Issue 763825 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 698156
Owner: ----
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Address bar spoofing with drag/drop and long response time.

Reported by mishra.d...@gmail.com, Sep 11 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0

Steps to reproduce the problem:
Upstream/Reference Bug :  660498 

FYI looks like this still works.
The attached exploit still WFM in,61.0.3163.79 (Official Build) (64-bit)

What is the expected behavior?

What went wrong?
Request you to please have a look, attaching Video POC for same.

Did this work before? N/A 

Chrome version: 61.0.3163.79 (Official Build) (64-bit) (cohort: 61_Win_79)  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: 24.0.0.189 internal-not-yet-present
 
Spoof.html
303 bytes View Download
Video Poc
Chrome.avi
235 KB Download
Cc: creis@chromium.org
Components: UI>Browser>Navigation UI>Browser>Omnibox
Summary: Address bar spoofing with drag/drop and long response time. (was: Address bar spoofing with long response time.)
I believe this is exactly the same as  Issue 698156 .

Comment 3 by creis@chromium.org, Sep 11 2017

Mergedinto: 698156
Status: Duplicate (was: Unconfirmed)
Agreed, this is the same as  issue 698156 , which is to say, it's like the original report in  issue 660498  (before the no-user-interaction version was added in comment 5).

See https://bugs.chromium.org/p/chromium/issues/detail?id=698156#c8 for explanation.
Project Member

Comment 4 by sheriffbot@chromium.org, Dec 19 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment