Download Protection Bypass On Chrome Latest
Reported by
narendra...@gmail.com,
Apr 16 2018
|
||||
Issue descriptionVERSION Chrome Version: Latest + stable Operating System: Android 8.0.1 One Plus 5 REPRODUCTION CASE Open Chrome app Navigate to this link http://shurll.com/942i2 you will see user never get a prompt for any warning like malicious content or apk Expected results : User should be warned before downloading any APK file from the internet Obeserved Results : An malicious APK file will get start downloading without consent of target user
,
Apr 18 2018
Please try to reproduce in Chrome Android I think it is not mentioned anywhere in Google VRP Download protection bypass for apk Any APK can be downloaded without user consent Attaching my Chrome version
,
Apr 18 2018
Thank you for providing more feedback. Adding the requester to the cc list. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Apr 18 2018
Thanks. I did try it on Chrome for Android but couldn't reproduce this. Android verifies that an APK is safe to install before allowing the installation so not showing a download warning in Chrome is acceptable.
,
Apr 23 2018
Please try it again Did you repeated same steps as shown in my attached video poc
,
Apr 23 2018
Could you please mention what steps you are following
,
Apr 23 2018
Here's what I did: Open http://shurll.com/942i2 on Chrome Canary for Android. What happened: Previously, it was redirecting to google.com homepage. Today, it is redirecting to playperks.net/... No downloads happened in either case.
,
Jul 14
please try on chrome stable latest version You are trying on canary unstable version
,
Jul 14
Or if above not works Please use Indian IP I am able to reproduce on every fresh install
,
Jul 14
see my earlier attached video every time that app got downloaded without any prompt
,
Jul 14
,
Jul 14
above POC was demonstrated on Latest Chrome Canary
,
Jul 26
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||
►
Sign in to add a comment |
||||
Comment 1 by vakh@chromium.org
, Apr 16 2018