Issue metadata
Sign in to add a comment
|
Security: IDN URL Spoofing with Myanmar character "ဒ" (U+1012)
Reported by
chromium...@gmail.com,
May 28 2018
|
||||||||||||||||||||||||
Issue descriptionVERSION Chrome Version: 69.0.3442.0 (Official Build) canary (64-bit) Operating System: Mac - see issue 811117 . REPRODUCTION CASE http://xn--16-z0j.com/ this should be shown in punycode instead of 16ဒ.com (163.com in the top 10k list).
,
May 30 2018
I believe the fix is similar to https://chromium-review.googlesource.com/c/chromium/src/+/1055894 Since jshin is transitioning, would any of the CCs be interested in this one? Otherwise I can give it a shot.
,
May 30 2018
,
May 31 2018
,
May 31 2018
,
Jun 7 2018
,
Jun 8 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/d616695bd68610e75b90d734d72d42534bf01b82 commit d616695bd68610e75b90d734d72d42534bf01b82 Author: Mustafa Emre Acer <meacer@chromium.org> Date: Fri Jun 08 19:19:41 2018 Add confusability mapping entries for Myanmar and Georgian U+10D5 (ვ), U+1012 (ဒ) => 3 Bug: 847242 , 849398 Test: components_unittests --gtest_filter=*IDN* Change-Id: I9abb8560cf1c9e8e5e8d89980780b89461f7be52 Reviewed-on: https://chromium-review.googlesource.com/1091430 Reviewed-by: Peter Kasting <pkasting@chromium.org> Commit-Queue: Mustafa Emre Acer <meacer@chromium.org> Cr-Commit-Position: refs/heads/master@{#565709} [modify] https://crrev.com/d616695bd68610e75b90d734d72d42534bf01b82/components/url_formatter/idn_spoof_checker.cc [modify] https://crrev.com/d616695bd68610e75b90d734d72d42534bf01b82/components/url_formatter/url_formatter_unittest.cc
,
Jun 8 2018
Verified the fix in 69.0.3454.0 (Developer Build) (64-bit), http://xn--16-z0j.com/ is shown in punycode instead of http://16ဒ.com.
,
Jun 12 2018
It's now picked up by Canary, closing.
,
Jun 13 2018
,
Jun 18 2018
,
Jun 19 2018
,
Jun 19 2018
This bug requires manual review: M68 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), kariahda@(iOS), bhthompson@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 19 2018
which OS's is this impacting?
,
Jun 19 2018
Must be all but not sure about iOS
,
Jun 19 2018
Approved branch:3440
,
Jun 20 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/93c0d219306d70faf545afd6baf3e6f389c76f55 commit 93c0d219306d70faf545afd6baf3e6f389c76f55 Author: Mustafa Emre Acer <meacer@chromium.org> Date: Wed Jun 20 17:45:43 2018 Add confusability mapping entries for Myanmar and Georgian U+10D5 (ვ), U+1012 (ဒ) => 3 TBR=meacer@chromium.org (cherry picked from commit d616695bd68610e75b90d734d72d42534bf01b82) Bug: 847242 , 849398 Test: components_unittests --gtest_filter=*IDN* Change-Id: I9abb8560cf1c9e8e5e8d89980780b89461f7be52 Reviewed-on: https://chromium-review.googlesource.com/1091430 Reviewed-by: Peter Kasting <pkasting@chromium.org> Commit-Queue: Mustafa Emre Acer <meacer@chromium.org> Cr-Original-Commit-Position: refs/heads/master@{#565709} Reviewed-on: https://chromium-review.googlesource.com/1108380 Reviewed-by: Mustafa Emre Acer <meacer@chromium.org> Cr-Commit-Position: refs/branch-heads/3440@{#464} Cr-Branched-From: 010ddcfda246975d194964ccf20038ebbdec6084-refs/heads/master@{#561733} [modify] https://crrev.com/93c0d219306d70faf545afd6baf3e6f389c76f55/components/url_formatter/idn_spoof_checker.cc [modify] https://crrev.com/93c0d219306d70faf545afd6baf3e6f389c76f55/components/url_formatter/url_formatter_unittest.cc
,
Jun 21 2018
I'm afraid the VRP panel declined to award for this report.
,
Jul 23
,
Aug 28
,
Sep 19
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 19
,
Jan 4
|
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, May 28 2018Components: UI>Browser>Omnibox UI>Security>UrlFormatting
Labels: Security_Impact-Stable
Owner: js...@chromium.org
Status: Assigned (was: Unconfirmed)