Issue metadata
Sign in to add a comment
|
Security: Cross Site Scripting by entering JavaScript in the omnibox
Reported by
melvinva...@gmail.com,
Nov 30 2017
|
||||||||||||||||||||
Issue description
VULNERABILITY DETAILS
A cross site scripting security bug was observed in the search bar of chrome browser
VERSION
Chrome Version: 62.0.3202.94 (Official Build) (64-bit)
Operating System: Windows 7 Enterprise
REPRODUCTION CASE
1. Open a new tab in Google Chrome Browser
2. Insert the payload in the search bar (Please note that I have typed these payload directly into the browser search bar and not copy-pasted it)
Payloads used:
javascript:alert(0)
javascript:alert(document.cookie)
javascript:alert(document.domain)
javascript:prompt(document.cookie)
To reproduce please type the above mentioned payloads
3. Cross site scripting in browser is show in the screenshots attached.
NOTE: I have not changed any of the default settings in this Google Chrome. Also the payload was easily executed in my browser
Please provide insight on the above issue.If this is not a valid security bug, please give me an understanding why this has happened.
Thanks Google Security Team,
,
Feb 22 2018
,
Mar 9 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, Nov 30 2017Summary: Security: Cross Site Scripting by entering JavaScript in the omnibox (was: Security: Cross Site Scripting )