Issue metadata
Sign in to add a comment
|
Security: Phishing Url blocked by desktop chrome but not on Android Chrome.
Reported by
gw.preto...@gmail.com,
Jun 5 2018
|
||||||||||||||||||||||
Issue descriptionVERSION Chrome Version: Latest version on Play Store. Operating System: OnePlus 5t Android 8.1 Security Patch level 1 May 2018 REPRODUCTION CASE See unicode url at the bottom: If url with Unicode chars is opened in Chrome on windows it is blocked, but if opened in chrome on Android it is not blocked, The "K" in this URL is replaced by a unicode character, this can be seen with the small dot below the "k" in the url below http://www.volḳswagen.com/ attached file shows its almost impossible to detect with the naked eye, even when inspecting with dev toolbar.
,
Jun 5 2018
Thanks for reporting the issue. Filed internally as http://b/109743476 for Safe Browsing. - There's nothing for Chrome to do here. - The URL is rendered in Punycode so the risk of Phishing is low. - The URL seems to have been stood up very recently so it is unlikely that it has done widespread harm. Given all that, I am marking it as WontFix.
,
Sep 12
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by palmer@chromium.org
, Jun 5 2018Components: Services>Safebrowsing
Labels: Security_Impact-Stable M-69 OS-Android Pri-1
Owner: vakh@chromium.org
Status: Assigned (was: Unconfirmed)