New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 881747 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 719856
Owner:
Closed: Sep 10
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows , Mac
Pri: 2
Type: Bug-Security



Sign in to add a comment

Security: url spoof in slow network

Reported by ma7h1a...@gmail.com, Sep 7

Issue description

VULNERABILITY DETAILS
unbeforeunload function could be abused in a slow network , casued url spoof

VERSION
Chrome Version: 69
Operating System: windows 7 / OS X

see online demo http://f.3cm.me/r/chrome_spoof.html
the reproduce step : see chrome_spoof.gif
 
chrome_spoof.gif
602 KB View Download
Cc: creis@chromium.org cthomp@chromium.org a...@chromium.org nasko@chromium.org
Components: UI>Browser>Navigation
Labels: Security_Severity-Low Security_Impact-Stable OS-Mac OS-Windows Pri-2
Owner: k...@chromium.org
Status: Assigned (was: Unconfirmed)
Adding some people that have worked on navigation. Please assign an owner if you are the wrong people to add!

Setting to low severity since there is not very much time to exploit this and the page still looks like it's loading.
Mergedinto: 719856
Owner: creis@chromium.org
Status: Duplicate (was: Assigned)
This has come up before, but basically there are mitigating factors since the attacker doesn't know the user's destination URL, and the browser still shows the navigation is in progress.  In more detail:

In  issue 698156  (WontFix), we pointed out that the browser intentionally shows user-initiated URLs while they're pending.  The current page can change its appearance during that time, but there are cues that the navigation is still in progress (e.g., spinner going, no lock icon).  Discussion:
https://bugs.chromium.org/p/chromium/issues/detail?id=698156#c8

Similarly, in  issue 719856  (WontFix), we pointed out this boils down to the omnibox trying to do two jobs at once (showing where you're going and where you are).  We tried making progress on hard UX problems there (and offline), but no luck so far.  Discussion:
https://bugs.chromium.org/p/chromium/issues/detail?id=719856#c11

Marking as a duplicate of the latter, since any discussion to improve the UX should probably happen there.
Project Member

Comment 3 by sheriffbot@chromium.org, Dec 18

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment