New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 853131 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: 2018-06-18
OS: Windows
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Clickjacking on any website (ignoring x-frame-options)

Reported by qie...@gmail.com, Jun 15 2018

Issue description

VULNERABILITY DETAILS
Hello, I noticed that in the latest update google chrome ignores x-frame-options: origin (or deny), you can load any site in the frame. Firefox at this time reacts as needed (screenshot).
Steps to play:
1. Click the link https://securityz.net/cj.html.
2. Enter any site with x-frame-options, for example google.com (I remember, before google bug bounty paid $ 5000 for clickjacking google.com).

Impact: Clickjacking on any site.

VERSION
Chrome Version: 67.0.3396.87 (latest)
Operating System: OS Windows

PoC video: https://youtu.be/ORnNLpE0TZQ
 
ice_screenshot_20180615-114912.png
166 KB View Download
ice_screenshot_20180615-114929.png
54.2 KB View Download
ice_screenshot_20180615-114951.png
638 KB View Download

Comment 1 by wfh@chromium.org, Jun 15 2018

Cc: mkwst@chromium.org
Components: Blink>SecurityFeature>XFrameOptions Blink>SecurityFeature
Thanks for your report.

In general, we prefer PoCs to be uploaded, rather than hosted, but I have attached it here.
cj.html
2.4 KB View Download

Comment 2 by mkwst@chromium.org, Jun 15 2018

Cc: alex...@chromium.org arthurso...@chromium.org
This doesn't reproduce for me in 67.0.3396.87 or Canary. Do you have any particular flags enabled?

CCing alexmos@ and arthursonzogni@, as I'm already OOO and away from a computer for the evening, just in case this reproduces for them.

Comment 3 by wfh@chromium.org, Jun 15 2018

Labels: Needs-Feedback Unreproducible OS-Windows
I also cannot repro with 67.0.3396.87 (Official Build) (64-bit) (cohort: Stable) running with --disable-extensions in a new profile.

I get:

Refused to display 'https://www.google.com/' in a frame because it set 'X-Frame-Options' to 'sameorigin'.

OP: can you paste you chrome://version "variations" line. it should be a long list of hex numbers.
No repro for me either (I checked Stable, Canary, and ToT).  OP: does it still repro if you start Chrome with --disable-extensions?

Comment 5 by wfh@chromium.org, Jun 15 2018

NextAction: 2018-06-18
Thanks for everyone testing this.

I'll close this as unreproducible next week, if no further details come in.

Comment 6 by qie...@gmail.com, Jun 15 2018

Hmm, I just checked it in incognito mode (no extensions) and the bug did not work https://youtu.be/9XTjarhb4UI . I think this ignoring of x-frame-options is due to some kind of extension, I'll try to find it tomorrow.
Project Member

Comment 7 by sheriffbot@chromium.org, Jun 15 2018

Cc: wfh@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 8 by wfh@chromium.org, Jun 15 2018

Status: WontFix (was: Unconfirmed)
Okay, thanks for the update. That seems like quite a bad thing for an extension to do, I'd be interested which one is causing it, but it sounds like this can be closed WontFix. I'll keep an eye on the bug though if you have further updates.

Comment 9 by qie...@gmail.com, Jun 15 2018

Interesting that https://gmail.com can't load because of CSP errors
ice_screenshot_20180616-001055.png
150 KB View Download

Comment 10 by qie...@gmail.com, Jun 15 2018

okay.
The NextAction date has arrived: 2018-06-18
Project Member

Comment 12 by sheriffbot@chromium.org, Sep 22

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment