New issue
Advanced search Search tips

Issue 833314 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Download Protection Bypass On Chrome Latest

Reported by narendra...@gmail.com, Apr 16 2018

Issue description


VERSION
Chrome Version: Latest + stable
Operating System: Android 8.0.1 One Plus 5

REPRODUCTION CASE

Open Chrome app 
Navigate to this link

http://shurll.com/942i2

you will see user never get a prompt for any warning like malicious content or apk 

Expected results : User should be warned before downloading any APK file from the internet

Obeserved Results : An malicious APK file will get start downloading without consent of target user

 
 
2018_04_16_13_26_33.mp4
14.9 MB View Download

Comment 1 by vakh@chromium.org, Apr 16 2018

Labels: Needs-Feedback
I am unable to reproduce this. When I open that link, it just redirects to google.com

1. Can you please verify that the report is still accurate?
2. Share the APK with us? It doesn't appear from the video that the APK is malicious.
Please try to reproduce in Chrome Android


I think it is not mentioned anywhere in Google VRP
Download protection bypass for apk
Any APK can be downloaded without user consent

Attaching my Chrome version
Screenshot_20180418-225020.jpg
525 KB View Download
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 18 2018

Cc: vakh@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 4 by vakh@chromium.org, Apr 18 2018

Status: WontFix (was: Unconfirmed)
Thanks. I did try it on Chrome for Android but couldn't reproduce this.

Android verifies that an APK is safe to install before allowing the installation so not showing a download warning in Chrome is acceptable.
Please try it again 
Did you repeated same steps as shown in my attached video poc
Could you please mention what steps you are following 

Comment 7 by vakh@chromium.org, Apr 23 2018

Here's what I did: Open http://shurll.com/942i2 on Chrome Canary for Android.

What happened:
Previously, it was redirecting to google.com homepage.
Today, it is redirecting to playperks.net/...

No downloads happened in either case.
please try on chrome stable latest version
You are trying on canary unstable version 
Or if above not works 
Please use Indian IP 

I am able to reproduce on every fresh install 
see my earlier attached video
every time that app got downloaded without any prompt
2018_07_15_01_34_32.mp4
7.8 MB View Download
above POC was demonstrated on Latest Chrome Canary
Project Member

Comment 13 by sheriffbot@chromium.org, Jul 26

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment