New issue
Advanced search Search tips

Issue 882154 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 881694
Owner: ----
Closed: Sep 9
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: misleading hostnames in Chrome 69

Reported by benburh...@gmail.com, Sep 8

Issue description

VULNERABILITY DETAILS
Chrome 69 defies its own security policy by misrepresenting the URL.

VERSION
Chrome Version: 69.0.3497.81 (Official Build) (64-bit)
Operating System: Windows 7 Ultimate 6.1.7601 SP1 build 7601

REPRODUCTION CASE
1.) Navigate to https://www.tumblr.com/. Observe the official, authoritative web site published by the company behind the domain name tumblr.com.
2.) With default settings and flags in Chrome 69, note that the subdomain is obscured.
3.) Navigate to https://m.tumblr.com/. Observe the unofficial, user-created arbitrary content published by a customer of the company behind the domain name tumblr.com.
4.) With the same default settings, flags, and Chrome version, note that the subdomain is obscured, and that the URL displayed is identical to the one displayed in Step 2.

The identity of a page is not just contained its topmost levels of the hostname. This is a severe vulnerability issue that violates the trust a user expects to place in their user agent and the pages it navigates to.

As another example, assume someone is able to place arbitrary content on https://www.www.google.com. Observe that such a site is now identical to the well-known https://www.google.com as far as the chrome section of the application is concerned.

The chrome area is sacred, intended to be implicitly trusted and not easily tampered with, and the browser should not erode the confidence users have been taught to place in it.
 
References: https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#where-are-the-security-indicators-located-in-the-browser-window

"Furthermore, Chrome can only guarantee that it is correctly representing URLs and their origins at the end of all navigation. Quirks of URL parsing, HTTP redirection, and so on are not security concerns unless Chrome is misrepresenting a URL or origin after navigation has completed."

'Misrepresending a URL or origin after navigation has completed' is exactly what Chrome 69 is doing.
Mergedinto: 881694
Status: Duplicate (was: Unconfirmed)
Hello! Thank you for the report. This issue has been reported previously and is being tracked in the duplicate issue. Thanks!
Project Member

Comment 3 by sheriffbot@chromium.org, Dec 17

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment