New issue
Advanced search Search tips

Issue 804180 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Security



Sign in to add a comment

access to sites without a domain

Reported by lubokhin...@gmail.com, Jan 21 2018

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36

Steps to reproduce the problem:
1. open a browser
2. enter any address in the search bar - " example/"
3. working site : http://ai/

What is the expected behavior?
move me into a search and not attempt to open a site

What went wrong?
the browser perceives any word with a / sign at the end as a site and tries to transfer me to it

Did this work before? N/A 

Chrome version: 63.0.3239.132  Channel: stable
OS Version: OS X 10.13.2
Flash Version:
 
10 мб.mov
2.9 MB Download
Components: UI>Browser>Omnibox
Status: WontFix (was: Unconfirmed)
Thanks for the report.  This is feature of the omnibox, where it interprets anything that looks like a domain name, and that has a trailing slash, as a URL.

I'll close this bug as WAI, but if you know of a security vulnerability caused by this heuristic, please file another bug. Thanks.
Project Member

Comment 2 by sheriffbot@chromium.org, Apr 30 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment