Issue metadata
Sign in to add a comment
|
Security: http authentication spoof on chrome android
Reported by
ma7h1a...@gmail.com,
Sep 14
|
||||||||||||||||||||||
Issue descriptiononline demo : http://www.applestore.ac.cn/r/spoof.html see 401_spoof.jpg the popup should be closed after navigation VERSION Chrome Version: chrome 69 Operating System: android
,
Sep 14
Have we tried repoing in Chrome 68? It's possible that some auto-dismissing logic doesn't trigger anymore? Although a quick look doesn't suggest this would ever have been dismissed. That is unless we had some global dialog dismisser but I don't know if that's even possible, +ted? Looks like a legitimate issue. What's the turnaround expected, rsesek? Would we want to try and include in a m69-respin or m70? Not sure how to verify whether the auth credentials end up getting used or are invalidated at a later stage?
,
Sep 17
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/f40a8c947f6f13ea97baa3d7967e033f75587b41 commit f40a8c947f6f13ea97baa3d7967e033f75587b41 Author: Ted Choc <tedchoc@chromium.org> Date: Mon Sep 17 18:31:56 2018 Auto-dismiss http auth dialogs on navigation for Android. BUG= 884179 Change-Id: I18287e9c641045d5a74f3804e06ca17485e38957 Reviewed-on: https://chromium-review.googlesource.com/1227482 Commit-Queue: Ted Choc <tedchoc@chromium.org> Reviewed-by: Yaron Friedman <yfriedman@chromium.org> Cr-Commit-Position: refs/heads/master@{#591747} [modify] https://crrev.com/f40a8c947f6f13ea97baa3d7967e033f75587b41/chrome/android/java/src/org/chromium/chrome/browser/ChromeHttpAuthHandler.java [modify] https://crrev.com/f40a8c947f6f13ea97baa3d7967e033f75587b41/chrome/android/java/src/org/chromium/chrome/browser/LoginPrompt.java [modify] https://crrev.com/f40a8c947f6f13ea97baa3d7967e033f75587b41/chrome/android/java_sources.gni [add] https://crrev.com/f40a8c947f6f13ea97baa3d7967e033f75587b41/chrome/android/javatests/src/org/chromium/chrome/browser/ChromeHttpAuthHandlerTest.java [modify] https://crrev.com/f40a8c947f6f13ea97baa3d7967e033f75587b41/chrome/browser/ui/android/chrome_http_auth_handler.cc [modify] https://crrev.com/f40a8c947f6f13ea97baa3d7967e033f75587b41/chrome/browser/ui/android/chrome_http_auth_handler.h [modify] https://crrev.com/f40a8c947f6f13ea97baa3d7967e033f75587b41/chrome/browser/ui/android/login_handler_android.cc
,
Sep 17
,
Sep 18
,
Sep 24
,
Oct 4
*** Boilerplate reminders! *** Please do NOT publicly disclose details until a fix has been released to all our users. Early public disclosure may cancel the provisional reward. Also, please be considerate about disclosure when the bug affects a core library that may be used by other products. Please do NOT share this information with third parties who are not directly involved in fixing the bug. Doing so may cancel the provisional reward. Please be honest if you have already disclosed anything publicly or to third parties. Lastly, we understand that some of you are not interested in money. We offer the option to donate your reward to an eligible charity. If you prefer this option, let us know and we will also match your donation - subject to our discretion. Any rewards that are unclaimed after 12 months will be donated to a charity of our choosing. *********************************
,
Oct 4
Nice one, ma7h1as.l@ - $1,000 for this report.
,
Oct 4
,
Oct 26
,
Oct 26
This bug requires manual review: M71 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: benmason@(Android), kariahda@(iOS), kbleicher@(ChromeOS), govind@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 26
The CL already landed in M70 (71.0.3555.0), removing spurious merge bits.
,
Dec 3
,
Dec 11
,
Dec 11
,
Dec 25
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by rsesek@chromium.org
, Sep 14Labels: Security_Severity-Medium M-71 Security_Impact-Stable FoundIn-69 OS-Android Pri-1
Owner: yfried...@chromium.org
Status: Assigned (was: Unconfirmed)