New issue
Advanced search Search tips

Issue 808873 link

Starred by 2 users

Issue metadata

Status: Duplicate
Owner:
Closed: Feb 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Mac-only UNKNOWN crash in wikipedia.org

Reported by jackwill...@gmail.com, Feb 4 2018

Issue description

Google Chrome	66.0.3339.0 (Official Build) canary (64-bit)
Revision	eede49c2a7bfdd0a69d5254981bf629765ca57f7-refs/heads/master@{#534290}
OS	Mac OS X

1. Run Chrome with --flag-switches-begin --autoplay-policy=user-gesture-required-for-cross-origin --enable-experimental-web-platform-features --enable-translate-new-ux --enable-features=ClickToOpenPDFPlaceholder,ClipboardContentSetting,WebAssembly --flag-switches-end

2. Visit https://en.wikipedia.org/wiki/Catholic_Church
3. On the right, click on "Vatican City" (below the picture) 
4. Crash tab

I'm not really sure if this is a security bug, because I don't have a Mac ASAN build to check this crash.

Crash/b8419320d3339d10
Crash/87c1d37bfe296552
 
Both of these appear to be crashes with stacks in AppKit's NSOverlayScrollerImp.

I'm not able to reproduce a crash here without those flags set-- are you? What about if only enable-translate-new-ux is set?

Comment 2 Deleted

I'm able to reproduce the crash only with enabling --enable-experimental-web-platform-features.

Comment 4 by palmer@google.com, Feb 5 2018

Components: Blink>Internals
Labels: OS-Mac
Owner: ellyjo...@chromium.org
Status: Assigned (was: Unconfirmed)
ellyjones: Can you please find a person to handle this? Thanks! I suspect it may not be a security bug, but will await further investigation from you/your crew.
Mergedinto: 809142
Status: Duplicate (was: Assigned)
The crashing stack is identical to 809142, so I'm marking this as a duplicate of that. This bug is only present with --enable-experimental-web-platform-features & is a deliberate crash (via ZombieObjectCrash) when trying to access a freed object. I think the overall security risk of it is quite low.
Project Member

Comment 6 by sheriffbot@chromium.org, May 15 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment