New issue
Advanced search Search tips

Issue 802157 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Read cookies from cross-domain frame

Reported by xiaopig...@gmail.com, Jan 16 2018

Issue description

vim poc.html

<iframe src="http://xiaopigfly.com/" onload="alert(frames[0].document.cookie)">

You need to visit http: //ip/poc.html (poc.html on the server)


you can look pic: WX20180116-151238@2x.png

and than you can look WX20180116-151555@2x.png Safari is error


Normally not allowed to do so, and ip different ports can also cross-domain in chrome

VERSION
Chrome Version: 63.0.3239.132
Operating System: macOS



 
WX20180116-151555@2x.png
250 KB View Download
look is pic 
WX20180116-151957@2x.png
154 KB View Download
example.com need A resolution to the server, use this server ip4 address to access poc.html

Components: Blink>SecurityFeature>SameOriginPolicy
In Chrome 64 and Chrome 65 visiting http://47.52.62.66/poc1.html shows

Uncaught DOMException: Blocked a frame with origin "http://47.52.62.66" from accessing a cross-origin frame.
    at HTMLIFrameElement.onload (http://47.52.62.66/poc1.html:1:96)

Unfortunately, I don't have a Chrome 63 instance any longer.

Summary: Security: Read cookies from cross-domain frame (was: Security:Chrome cross-domain vulnerability)
I wasn't able to reproduce this on Windows Chrome 63. 
Is macOS system chrome 63
Very strange, I also suggested in another macOS not cross-domain, but I have allowed cross-domain from another computer!
I am not sure exactly what caused this

Status: WontFix (was: Unconfirmed)
On Chrome M63 on Mac, visiting the URL in #3 shows the same result as in #3:

Uncaught DOMException: Blocked a frame with origin "http://47.52.62.66" from accessing a cross-origin frame.
    at HTMLIFrameElement.onload (http://47.52.62.66/poc1.html:1:96)

I'm marking as WontFix. If you have a new working repro, please file another bug. Thanks.
Project Member

Comment 9 by sheriffbot@chromium.org, Apr 25 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment