New issue
Advanced search Search tips

Issue 803166 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 493159
Owner: ----
Closed: Jan 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Clipboard contents can be read unexpectedly via clickjacking on linux

Reported by infinite...@gmail.com, Jan 17 2018

Issue description

VULNERABILITY DETAILS
A carefully crafted webpage can use a link and a hidden text area to extract the current contents of a user's clipboard when the user attempts to open a link in a new tab (middle click).

VERSION
Chrome Version: 63.0.3239.84 Stable (Chromium)
Operating System: Xubuntu 16.04

REPRODUCTION CASE
Attached is an example webpage which demonstrates a basic version of this issue.
 
clipboard-click-jacking.html
1.2 KB View Download
Components: Blink>DataTransfer
Labels: Security_Impact-Stable OS-Linux
Status: Untriaged (was: Unconfirmed)
Summary: Security: Clipboard contents can be read unexpectedly via clickjacking on linux (was: Security: Clipboard contents can be read unexpectedly via clickjacking on linux)
Clever.
I believe this is effectively dupe of  Issue 493159 .
Mergedinto: 493159
Status: Duplicate (was: Untriaged)
yup
Seeing as I do not have permission to view #493159, could I ask what the consensus on the issue seems to be?
Project Member

Comment 5 by sheriffbot@chromium.org, May 25 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment