New issue
Advanced search Search tips

Issue 875127 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 778352
Owner:
Closed: Aug 20
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Excessive disk usage triggered via variable fonts

Reported by davidog...@gmail.com, Aug 17

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://chromium.googlesource.com
/chromium/src/+/master/docs/security/faq.md

Please see the following link for instructions on filing security bugs:
https://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Sorry, this won't be a detailed account. I haven't spent the time to verify that it works but it looks pretty exploitable.

I came across: https://twitter.com/DesignJokes/status/1029992922580574208 where Wentin points out that more than 40G of disk space is used up when playing with variable fonts.

Potential exploit: an attacker forces user to reboot or relaunch chrom*.

Why is this bad: While more benign (no data lost), the UX is completely destroyed and it seems easy to trigger this in the background (invisibly) so the user has no idea what's causing the sudden increase in disk usage - forcing restarts and severe distractions.


VERSION
Chrome Version: no idea but looks like all current AFAICT
Operating System: no idea but looks like all

REPRODUCTION CASE
Please include a demonstration of the security bug, such as an attached
HTML or binary file that reproduces the bug when loaded in Chrome. PLEASE
make the file as small as possible and remove any content not required to
demonstrate the bug.

https://twitter.com/DesignJokes/status/1029992922580574208

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace *with symbols*, registers,
exception record]
Client ID (if relevant): [see link above]

n/a

Thanks for the good work!
 
Components: Blink>Fonts
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Summary: Excessive disk usage triggered via variable fonts (was: Security: Excessive disk usage triggered via variable fonts)
Thanks for the report, as per our security guidelines this is not a Security bug (https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Are-denial-of-service-issues-considered-security-bugs-). I'll route this to the fonts team so it can get triaged, though they might need more details to address this.
Owner: drott@chromium.org
Status: Assigned (was: Unconfirmed)
Mergedinto: 778352
Status: Duplicate (was: Assigned)
davidogutu, thanks for the report. We were already tracking this as an unbounded memory growth problem in issue 778352.

Sign in to add a comment