New issue
Advanced search Search tips

Issue 786853 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: Favicon for bookmark changes to incorrect icon

Reported by va7...@gmail.com, Nov 20 2017

Issue description

VULNERABILITY DETAILS
When using Chrome browser with Facebook, Twitter, Linkedin, Instagram as bookmarks, the favicon from Twitter makes changes to other bookmark favicons.
Security_Severity: Low
Security_Impact: Unknown

VERSION
Chrome Version: 62.0.3202.94 (Official Build) (64-bit)
Operating System: Mac OS High Sierra 10.13.1 (17B48)

REPRODUCTION CASE
Start on Twitter page and then select another bookmark via by selecting clicking the favicon, the page gets loaded and the favicon changes from the original favicon to the Twitter favicon. Other than Facebook, the other bookmarks only had the change temporarily. The Facebook favicon would remain as Twitter throughout the time on page.

Browser was set to save passwords and log out was not conducted prior to changing pages.

Photo attached showing Twitter favicon for Facebook bookmark.





 
Screen Shot 2017-11-19 at 6.24.53 PM.png
24.4 KB View Download
Components: UI>Browser>Bookmarks
Summary: Security: Favicon for bookmark changes to incorrect icon (was: Security: Twitter controlling favicons)

Comment 2 by mmoroz@chromium.org, Nov 20 2017

Labels: Needs-Feedback
I cannot reproduce this on Mac using Version 62.0.3202.94 (Official Build) (64-bit).

Could you please provide more detailed instructions and / or record a video of how the issue occurs?
Labels: -Type-Bug-Security Type-Bug
Status: WontFix (was: Unconfirmed)
Mark as won't fix due to cannot repro. 
Please feel free to reopen this issue if you can provide more detailed repro steps.
Project Member

Comment 4 by sheriffbot@chromium.org, Mar 1 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment