Security: Chrome XSS XSS auditor Bypass
Reported by
new404er...@gmail.com,
May 21 2018
|
||||
Issue descriptionHello, I have Found A Bug On Chrome XSS Bypass POC Vist This link http://1cu.pw/xss/chrome.html?redir=%19Jav%09asc%09ript:https://google.com/%250Aconfirm%2528133.7*10%2529 Thanks
,
May 21 2018
,
May 21 2018
,
May 22 2018
,
May 22 2018
Able to reproduce the issue on chrome stable# 66.0.3359.181 and on latest chrome# 68.0.3436.0 using Windows-10, Ubuntu 14.04 and Mac 10.12.6. As the issue is seen from M-60(60.0.3112.0), hence considering this as Non-Regression issue. Thanks!
,
May 22 2018
is it not a vulnerability issue? thank you
,
May 22 2018
,
May 22 2018
I was seen... if any process please notify me Thank you
,
May 24 2018
The XSSAuditor is not able to defend against persistent XSS or DOM-based XSS. as explained https://chromium.googlesource.com/chromium/src/+/lkcr/docs/security/faq.md#Are-XSS-filter-bypasses-considered-security-bugs For all these cases, we get a script that eventually does: var redir = searchParams.get('redir'); if (redir !== null) { document.location = redir; } or var index = searchParams.get('index').toString(); eval('market.index=' + index); document.getElementById('p1').innerHTML = 'Current market index is ' + market.index + '.'; which are DOM-based XSS. |
||||
►
Sign in to add a comment |
||||
Comment 1 by mmoroz@chromium.org
, May 21 2018Components: Blink>SecurityFeature>XSSAuditor
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug