New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 784395 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Security
Team-Security-UX



Sign in to add a comment

Security: Address spoofing when switching away from tab and back (repro Issue 648117)

Reported by chromium...@gmail.com, Nov 13 2017

Issue description

VERSION
Chrome Version: Chromium 64.0.3268.0
Operating System: Mac

REPRODUCTION CASE
I can repro this only on Chromium build.

Apparently there is still something missing in  issue 648117 .

 
screen_1.mp4
346 KB View Download
spoof-simplified.html
1.1 KB View Download
I can observe the spoof text persist for longer than 4 seconds.

Comment 2 by est...@chromium.org, Nov 13 2017

Components: UI>Browser>Navigation UI>Security>UrlFormatting
Labels: Security_Severity-Low Security_Impact-Head OS-Mac
Owner: kenrb@chromium.org
Status: Assigned (was: Unconfirmed)
I can reproduce this sometimes on Mac Canary. kenrb, could you take a look please?

Marking as Low severity since the spoofed content doesn't persist for more than a few seconds and it doesn't reproduce reliably.
I can repro this reliably only on a trunk debug build not on Canary.

Comment 4 by kenrb@chromium.org, Nov 13 2017

#2: If it persists for no more than a few seconds then it is working as intended. There is a timer that clears the old page if the new one hasn't painted in sufficient time.

I haven't been able to reproduce but the my trunk build on Mac is a few days old. Maybe there is a very recent regression here.
On Canary it is working as intended (the spoof text persist only for 4 seconds), but on a trunk build doesn't work as intended.

Sometimes looks like it can take several tries to repo, and sometimes it switches the origin tab automatically via alert() (as in the first comment #0) but if it 
doesn't, Try to switch it quickly and wait a few seconds then back to the popup tab to make it appear again.
321342.mp4
530 KB View Download

Comment 6 by kenrb@chromium.org, Nov 13 2017

I still haven't been able to reproduce that, even after syncing and building again.

Do you see anything different in the log output, between times when it successfully repros and times when it does not?

It might be worth waiting to see if you can make it repro on tomorrow's Canary build, in case this is something very recently broken.

Comment 7 Deleted

Project Member

Comment 8 by sheriffbot@chromium.org, Nov 14 2017

Labels: Pri-2
Cc: carlosil@chromium.org
Are there any updates on the repro case for this one? Otherwise this seems like a candidate to Won'tFix
No more of repro this bug. please close as WontFix.
Status: WontFix (was: Assigned)
Project Member

Comment 12 by sheriffbot@chromium.org, May 24 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment