Issue metadata
Sign in to add a comment
|
Security: Address Bar Spoofing (IDN homograph )
Reported by
rbsoulhu...@gmail.com,
Oct 9 2017
|
||||||||||||||||||||||||||
Issue descriptionHi Chrome team, Armenian Small Letter Ho (U+0578) is not being handled correctly resulting in Address bar spoofing. Attached (spoof.png) հotel.com is not converted into it's punnycode equivalent (xn--otel-uff.com). Apparently firefox's latest version handles it correclty(spoof2.png) regards, Rafay
,
Oct 9 2017
(sorry, bad autocomplete for severity)
,
Oct 10 2017
,
Oct 10 2017
,
Oct 10 2017
Armenian is not allowed to mix with Latin in ToT (M63-to-be). See bug 726950 . The risk is low because major gTLDs and ccTLDs do not allow the registration of domains mixing Armenian and Latin. So, an example domain in the bug report cannot be registered.
,
Jan 17 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 19
|
|||||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||||
Comment 1 by och...@chromium.org
, Oct 9 2017Labels: Security_Severity-Critical Security_Impact-Stable
Owner: js...@chromium.org
Status: Assigned (was: Unconfirmed)