New issue
Advanced search Search tips

Issue 776730 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 445758
Owner: ----
Closed: Oct 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: JS Execution within PDFs

Reported by christop...@gmail.com, Oct 20 2017

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://chromium.googlesource.com
/chromium/src/+/master/docs/security/faq.md

Please see the following link for instructions on filing security bugs:
https://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
I was able to execute Javascript Code within the PDF Viewer during a Penetration Test on a Cloud Platform. I created a malicious PDF and the Javascript gets executed without asking for confirmation or a security warning. This vulnerability can be exploited to present the user a phishing page to a user to steal credentials from the user. 

VERSION
Chrome Version: Version 62.0.3202.62 (Official Build) (64-bit) + [stable]
Operating System: Linux version 4.10.0-37-generic (buildd@lgw01-amd64-037) (gcc version 5.4.0 20160609 (Ubuntu 5.4.0-6ubuntu1~16.04.4) ) #41~16.04.1-Ubuntu SMP Fri Oct 6 22:42:59 UTC 2017

REPRODUCTION CASE
Opening the pdf locally or through a webapplication executes the javascript within the pdf. This is not allowed in Firefox.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace *with symbols*, registers,
exception record]
Client ID (if relevant): [see link above]

 
test.pdf
998 bytes Download
chrome_js_01.png
20.9 KB View Download
chrome_js_02.png
67.6 KB View Download
Cc: tsepez@chromium.org
This has come up a few times.

I'm not aware of any attempt to prevent script execution in PDFs. As with HTML, a site serving this document type must either serve only trusted content, or should take efforts to ensure the document does not run within their origin (e.g. force download).
Components: Internals>Plugins>PDF
Mergedinto: 445758
Status: Duplicate (was: Unconfirmed)
Project Member

Comment 3 by sheriffbot@chromium.org, Jan 27 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment