New issue
Advanced search Search tips

Issue 875802 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 626951
Owner: ----
Closed: Aug 20
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: URL Redirection in Browser's Address Bar

Reported by mail.sri...@gmail.com, Aug 20

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://chromium.googlesource.com
/chromium/src/+/master/docs/security/faq.md

Please see the following link for instructions on filing security bugs:
https://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

VERSION
Chrome Version: [68.0.3440.106] + [stable]
Operating System: [MAC OS]

REPRODUCTION CASE

1) Open the address bar and access the below mentioned URL:
https://google.com+&@facebook.com/#
2) Then observe the bhaviour

Behavior:

Chrome is not able to interpret the URL hence gets redirected from Google.com to Facebook.com

 
Mergedinto: 626951
Status: Duplicate (was: Unconfirmed)
Thanks for the report, in this case Chrome is (correctly) trying to open facebook.com with google.com+ as a user name, which is correctly hidden. (See https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Is-Chrome-s-support-for-userinfo-in-HTTP-URLs-e.g.-http:-user:password-example.com-considered-a-vulnerability- and the duplicate bug).
Project Member

Comment 2 by sheriffbot@chromium.org, Nov 27

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment