New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 767914 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 756456
Owner:
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac , Fuchsia
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: Near homograph URL Spoofing with Tibetan U+0F35

Reported by chromium...@gmail.com, Sep 22 2017

Issue description

VERSION
Chrome Version: 63.0.3221.0
Operating System: Mac

REPRODUCTION CASE
This issue is similar to  bug 729979 .

PoC: http://xn--google-gsv.com/ (U+0F35 Tibetan)
 
Screen Shot 2017-09-22 at 17.42.22.png
131 KB View Download
Cc: js...@chromium.org mgiuca@chromium.org
Components: UI>Browser>Omnibox UI>Internationalization
Status: Untriaged (was: Unconfirmed)

Comment 2 by palmer@chromium.org, Sep 22 2017

Labels: Team-Security-UX Security_Severity-Medium Security_Impact-Stable OS-Android OS-Chrome OS-Fuchsia OS-Linux OS-Mac OS-Windows
Owner: js...@chromium.org
Status: Assigned (was: Untriaged)
jshin: Is this another instance of  Issue 703750 ? I'm not entirely sure (reading go/url-spoofs).
Project Member

Comment 3 by sheriffbot@chromium.org, Sep 23 2017

Labels: M-62
Project Member

Comment 4 by sheriffbot@chromium.org, Sep 23 2017

Labels: Pri-1

Comment 5 by js...@chromium.org, Sep 25 2017

.com and other Verisign controlled domains are not affected. This domain cannot be registered. 

This is yet another example of a Mac Tibetan font being broken. I thought we covered them all. Somehow U+0F35 is turned to blank. That is, this is   bug 714196  resurrected !

Anyway, this should be blocked on all platforms regardless of the way "Latin + U+0F35" is rendered because U+0F35 (http://unicode.org/cldr/utility/character.jsp?a=0F35 ) is a combining mark for Tibetan. 

Base + Combining mark of unrelated scripts should not be allowed. 
see http://bugs.icu-project.org/trac/ticket/13328 .




Comment 6 by js...@chromium.org, Sep 25 2017

Mergedinto: 756456
Status: Duplicate (was: Assigned)
Project Member

Comment 7 by sheriffbot@chromium.org, Jan 12 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment