New issue
Advanced search Search tips

Issue 784733 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 674848
Owner: ----
Closed: Nov 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: DOM cloberring using name attribute

Reported by saurabh....@gmail.com, Nov 14 2017

Issue description

VULNERABILITY DETAILS
Use of name attribute as 'domain' causes the latest Google Chrome to confuse as a result of which the DOM gets clobbered and document.domain API of JS gives incorrect value.

VERSION
Chrome Version: [Version 61.0.3163.100 (Official Build) (64-bit)] + [stable]
Operating System: [Windows 7]

REPRODUCTION CASE
Include the following HTML code in browser and observe:

<h3>Welcome to the real-time HTML editor!</h3>
<p>Type HTML in the textarea above, and it will magically appear in the frame below.</p>

<script>document.write(document.domain);</script>

<br>
<br>
<br>

<form name="domain"></form>

<br>
<br>
<br>


<script>document.write(document.domain);</script>
 
Chrome DOM Clobbering.PNG
23.4 KB View Download
Mergedinto: 674848
Status: Duplicate (was: Unconfirmed)
Thanks for the report. This is actually expected behaviour - see the duped bug. It does not affect the underlying document.domain, though if you can show that it does in some way (e.g. granting permissions that another domain has), please reopen.
Re 1:
I wish to see that original bug but I do not have the permission. Can you please grant me it?
Re 1:
I wish to see that original bug but I do not have the permission. Can you please grant me it?
Project Member

Comment 4 by sheriffbot@chromium.org, Feb 21 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment