New issue
Advanced search Search tips

Issue 827807 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Automatic code execution via downloads.open on macOS

Reported by chromium...@gmail.com, Mar 31 2018

Issue description

VERSION
Chrome Version: 67.0.3385.0 (Official Build) canary (64-bit)
Operating System: Mac

REPRODUCTION CASE
1. Install the extension.
2. The program (poc.dmg) should be opened without any warnings, and it's definitely bad behavior.
 
testcase.zip
2.1 KB Download
Components: UI>Browser>Downloads Platform>Extensions>API
Labels: OS-Mac
This description and POC are nearly identical to  Issue 793620 , a FIXED issue which was made public three hours before this report was filed. Please be sure to cite your sources when filing new reports.
I have some troubles reproducing this. The file link used in background.js doesn't seem to work. I've replaced the link with: https://download.sublimetext.com/Sublime%20Text%20Build%203143.dmg

Now I can get the file downloaded once I click on the extension icon, but the execution doesn't happen.

I used Version 65.0.3325.181 (Official Build) (64-bit) though, let me check with the canary build you mentioned.
Status: WontFix (was: Unconfirmed)
I also can't reproduce it with Version 67.0.3386.0 (Official Build) canary (64-bit). WontFix.

The POC sorta works for me in Chrome 66, except that the opened file is the one generated by the Data URI and thus it's harmless/rejected by the system.

In Chrome 67.0.3386.0, the repro fails with the console showing an error each time setTimeout fires:

Unchecked runtime.lastError while running downloads.open: User gesture required

I am still able to repro with the latest version of Canary.
Can you attach a screen recording using Quicktime?

Comment 8 Deleted

Comment 9 Deleted

Comment 10 Deleted

Project Member

Comment 11 by sheriffbot@chromium.org, Jul 10

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment