New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 841646 link

Starred by 2 users

Issue metadata

Status: Unconfirmed
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug



Sign in to add a comment

[DOS] Browser hangs on loading the code snippet

Reported by danly...@gmail.com, May 10 2018

Issue description

Steps to reproduce the problem:
I already reported this to google a weeks before but told me to better report this bug here at Chrome VRP

this is in reference to https://bugs.chromium.org/p/chromium/issues/detail?id=53176 where google has fixed the issue as a security but forgot to patch the same issue on their Android Platform

Summary:
Basically the function location.reload() is causing browser to hang as browser is not able to handle multiple reloads but similar issue cannot be seen in Chrome desktop Application as i am able to close the current tab.

Products affected:
Latest 
*Google Search 8.1.12.21.arm
*Chrome 66.0.3359.126

Steps To Reproduce:
Use the below code and save it as html file and then open it up on browser :-

<script>
open("");
setInterval('location.reload()',1);
</script>

Or

open up pop.html that i have attached: https://dan1337.altervista.org/pop.html

Thanks,

What is the expected behavior?
Crashes

What went wrong?
dos in Android Chrome

Crashed report ID: 

How much crashed? Just one tab

Is it a problem with a plugin? No 

Did this work before? N/A 

Chrome version: 68.0.3425.0  Channel: stable
OS Version: 66.0.3359.126
Flash Version: 

This is effectively affecting all mobile devices that runs Chrome as it restores every sites that was acessed recently, including our pop.html making Chrome browser unavailable..

Thanks,
 
Labels: Needs-triage-Mobile
Cc: sandeepkumars@chromium.org
Labels: Triaged-Mobile Needs-Feedback
Tested the issue using #66.0.3359.126 and #66.0.3359.158 on Android Samsung J7; 7.0.0 and could not reproduce the issue as per the steps mentioned below.

Steps:
1. Launched Browser
2. Navigated to https://dan1337.altervista.org/pop.html
3. No Crash is seen

@Reporter: Could you please update Chrome to latest version #66.0.3359.158 and check if you still face the issue? If so attach a Crash I'd from chrome://crashes for further triaging of the issue?

Thanks!!

Comment 3 by danly...@gmail.com, May 10 2018

Here is a video POC: https://drive.google.com/file/d/1b0d-4iIyxPx0Wx33yVvAPnrYTBGOwAaQ/view?usp=drivesdk

Tested on: Android 6, 6.0.1
With the following devices: samsung, vivo, oppo, myphone


Thanks,
Project Member

Comment 4 by sheriffbot@chromium.org, May 10 2018

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 5 by danly...@gmail.com, May 10 2018

As u will see in the video.. Chrome hangs ang starts crashing, even tho some features stopped working..

Thanks,

Comment 6 by danly...@gmail.com, May 10 2018

Thank you for your quick reply :)
Issue 841642 has been merged into this issue.
Components: UI>Browser>Navigation
This is likely to be basically the same as Issue 516995 and Issue 706432, whereby an endless flood of IPCs related to navigations make the browser UI unresponsive.

Comment 9 by danly...@gmail.com, May 19 2018

It's not... if you have read the reference that I shared with you:

"this is a browser crash; this part of the popup blocker code runs in the browser process, not the renderer."


Any updates now?

Comment 10 by nasko@chromium.org, May 21 2018

Reloads and popup blocker are unrelated. Based on the description in this bug, it does seem related to the IPC floods to the browser process.
Cc: jbanavatu@chromium.org
Labels: Needs-Feedback
Tested the issue using #66.0.3359.158 on Nexsus 5 6.0.1 and observed that no crash is seen on navigating to below url. Seems the provided url stoped its service.

@Reporter: Could you help us by providing Crash I'd from chrome://crashes for further triaging of the issue.Also provide any other url for which you are facing same issue.

Thanks!!

Comment 12 by danly...@gmail.com, Jun 15 2018

Hi team, the site is back up :)

And also, I am unable to look for crash Id cuz everytime I open the chrome browser it loads back the dan1337.altervista.org/pop.html and hangs up the browser again and again...

 I am using different browser to reply this ticket..
Btw.. You can use different url to reproduce this issue with these code:

<script>
open("");
setInterval('location.reload()',1);
</script>
Project Member

Comment 13 by sheriffbot@chromium.org, Jun 15 2018

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
hey team, ANy updates?

Sign in to add a comment