New issue
Advanced search Search tips

Issue 854661 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 93772
Owner: ----
Closed: Jun 2018
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Chrome Universal XSS using the hacked google account.

Reported by ksg97...@gmail.com, Jun 20 2018

Issue description

Hi, I can't English well :(
I will report on Korea language again if you want.


- VULNERABILITY DETAILS

Chrome has the Universal XSS vulnerability in the search engines.
Any javascript can execute by the search engine.

Look at the "POC.mp4".

- VERSION

Chrome Version: Version 67.0.3396.87 (Official Build) (64-bit) 
Operating System: ALL OS 
I tested it on Window 10 using the latest chrome version. 


- REPRODUCTION CASE

Look at the "FULL_POC.mp4".

1. Go to the "chrome://settings/searchEngines"
2. Remove the Default search engine. ('google.com' is default in my case)
3. Add search engine with xss payload.
"""
Search engine : Google
Keyword : google.com
URL with %s in place of query : javascript:alert(document.domain);var _="%s"  

↑↑↑ URL field is important! you can execute any javascript code. 
"""
4. Make default it
5. Search anything in the url bar.


- HACKING Scenario

The victim doesn't know chrome was hacked because the hacker can enter the original code like this: window.location="https://google.com/search?q=%s";


1. Hacker makes the hacked google account and shares account's id and password to any website. Victim login with this hacked account and 	
synchronizing the account setting.

The Victim's Chrome browser will be hacked.


2. Hacker set the exploit code into the public computers. (Many public computers in the Internet cafe or school .. etc)


Hacker can read e-mail when you move from the e-mail site like a Gmail.
Hacker can get the all of information on latest visited site.

As you already know that Hacker can do all of the exploits using javascript. 


Thank you.



 
POC.mp4
10.6 MB View Download
FULL_POC.mp4
15.3 MB Download

Comment 1 Deleted

Comment 2 Deleted

Comment 3 Deleted

Comment 4 Deleted

Comment 5 by och...@chromium.org, Jun 21 2018

Mergedinto: 93772
Status: Duplicate (was: Unconfirmed)
Hi, thanks for the report. Unfortunately we don't consider this to be a vulnerability, as if an attacker has compromised your account or if you're using a public computer, all bets are off. Please see https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#why-arent-compromised_infected-machines-in-chromes-threat-model

Comment 6 by ksg97...@gmail.com, Jun 21 2018

thank you for your comment
Project Member

Comment 7 by sheriffbot@chromium.org, Sep 27

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment