New issue
Advanced search Search tips

Issue 789874 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 81697
Owner: ----
Closed: Nov 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Cross Site Scripting by entering JavaScript in the omnibox

Reported by melvinva...@gmail.com, Nov 30 2017

Issue description

VULNERABILITY DETAILS
A cross site scripting security bug was observed in the search bar of chrome browser

VERSION
Chrome Version: 62.0.3202.94 (Official Build) (64-bit)
Operating System: Windows 7 Enterprise 

REPRODUCTION CASE

1. Open a new tab in Google Chrome Browser
2. Insert the payload in the search bar (Please note that I have typed these payload directly into the browser search bar and not copy-pasted it)

    Payloads used:

    javascript:alert(0)
    javascript:alert(document.cookie)
    javascript:alert(document.domain)
    javascript:prompt(document.cookie)

To reproduce please type the above mentioned payloads

3. Cross site scripting in browser is show in the screenshots attached.

NOTE: I have not changed any of the default settings in this Google Chrome. Also the payload was easily executed in my browser

Please provide insight on the above issue.If this is not a valid security bug, please give me an understanding why this has happened. 

Thanks Google Security Team,

 
cookie.PNG
116 KB View Download
domain.PNG
106 KB View Download
prompt.PNG
114 KB View Download
Status: WontFix (was: Unconfirmed)
Summary: Security: Cross Site Scripting by entering JavaScript in the omnibox (was: Security: Cross Site Scripting )
A user running script via the omnibox or the developer tools is not a vulnerability in Chrome.

Please see https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Does-entering-JavaScript_URLs-in-the-URL-bar-or-running-script-in-the-developer-tools-mean-there_s-an-XSS-vulnerability for discussion.

Mergedinto: 81697
Status: Duplicate (was: WontFix)
Project Member

Comment 3 by sheriffbot@chromium.org, Mar 9 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment