Security: IDN URL Spoofing with “ҙ” (U+0499)
Reported by
chromium...@gmail.com,
Apr 25 2018
|
|||||||||||||||||
Issue descriptionChrome Version: 68.0.3406.0 (Official Build) canary (64-bit) Operating System: macOS REPRODUCTION CASE - From issue 820068 https://xn--m1acaj3he48b8nnw.com >> https://ԝҙѕснооӏѕ.com Note: I believe this is the last character should be blocked in Chrome (Thanks to Jungshik Shin).
,
Apr 26 2018
,
Apr 30 2018
Ok. let's add it, too.
,
May 14 2018
,
May 14 2018
,
May 14 2018
Should we have a strategy for regularly migrating these extra confusability mappings to Unicode confusables.txt?
,
May 16 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/f8bc31acf099873ebc623e92908477f2e99c17f6 commit f8bc31acf099873ebc623e92908477f2e99c17f6 Author: Jungshik Shin <jshin@chromium.org> Date: Wed May 16 02:11:14 2018 Add a few more confusability mapping entries U+0153(œ) => ce U+00E6(æ), U+04D5 (ӕ) => ae U+0499(ҙ) => 3 U+0525(ԥ) => n Bug: 835554 , 826019 , 836885 Test: components_unittests --gtest_filter=*IDN* Change-Id: Ic89211f70359d3d67cc25c1805b426b72cdb16ae Reviewed-on: https://chromium-review.googlesource.com/1055894 Commit-Queue: Jungshik Shin <jshin@chromium.org> Reviewed-by: Peter Kasting <pkasting@chromium.org> Cr-Commit-Position: refs/heads/master@{#558928} [modify] https://crrev.com/f8bc31acf099873ebc623e92908477f2e99c17f6/components/url_formatter/idn_spoof_checker.cc [modify] https://crrev.com/f8bc31acf099873ebc623e92908477f2e99c17f6/components/url_formatter/top_domains/test_domains.list [modify] https://crrev.com/f8bc31acf099873ebc623e92908477f2e99c17f6/components/url_formatter/top_domains/test_skeletons.gperf [modify] https://crrev.com/f8bc31acf099873ebc623e92908477f2e99c17f6/components/url_formatter/url_formatter_unittest.cc
,
May 16 2018
Verified on 68.0.3433.0. Fixed.
,
May 17 2018
Will bake in canary and ask for merge to 67 branch.
,
May 18 2018
,
May 21 2018
,
May 29 2018
,
Jun 4 2018
I'm afraid the VRP panel declined to reward for this one, too.
,
Jun 8 2018
,
Jun 8 2018
This bug requires manual review: M68 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), kariahda@(iOS), bhthompson@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 8 2018
Merge Rejected - should be already in 3440 branch.
,
Jul 23
,
Aug 24
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Aug 28
,
Oct 19
,
Jan 4
|
|||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||
Comment 1 by elawrence@chromium.org
, Apr 25 2018Components: UI>Security>UrlFormatting UI>Internationalization
Labels: Security_Severity-Medium Security_Impact-Stable FoundIn-68 OS-Android OS-Chrome OS-Fuchsia OS-iOS OS-Linux OS-Mac OS-Windows Pri-1
Owner: js...@chromium.org
Status: Assigned (was: Unconfirmed)