New issue
Advanced search Search tips

Issue 884179 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Sep 17
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: http authentication spoof on chrome android

Reported by ma7h1a...@gmail.com, Sep 14

Issue description

online demo : http://www.applestore.ac.cn/r/spoof.html

see 401_spoof.jpg

the popup should be closed after navigation

VERSION
Chrome Version: chrome 69
Operating System: android
 
401_spoof.jpg
65.3 KB View Download
Components: UI>Browser>Navigation Internals>Network>Auth UI>Browser>Mobile
Labels: Security_Severity-Medium M-71 Security_Impact-Stable FoundIn-69 OS-Android Pri-1
Owner: yfried...@chromium.org
Status: Assigned (was: Unconfirmed)
I can confirm this on Android. On Desktop, the auth dialog is dismissed on the redirect, but on mobile it isn't.

yfriedman: According to git log, you upstreamed LoginPrompt.java and there've only been mechanical changes since. Can you take a look or suggest an owner for this bug?
Cc: tedc...@chromium.org
Have we tried repoing in Chrome 68? It's possible that some auto-dismissing logic doesn't trigger anymore? 

Although a quick look doesn't suggest this would ever have been dismissed. That is unless we had some global dialog dismisser but I don't know if that's even possible, +ted?

Looks like a legitimate issue. What's the turnaround expected, rsesek? Would we want to try and include in a m69-respin or m70? Not sure how to verify whether the auth credentials end up getting used or are invalidated at a later stage?
Project Member

Comment 3 by bugdroid1@chromium.org, Sep 17

Cc: -tedc...@chromium.org yfried...@chromium.org
Owner: tedc...@chromium.org
Status: Fixed (was: Assigned)
Project Member

Comment 5 by sheriffbot@chromium.org, Sep 18

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Labels: reward-topanel
Labels: -reward-topanel reward-unpaid reward-1000
*** Boilerplate reminders! ***
Please do NOT publicly disclose details until a fix has been released to all our users. Early public disclosure may cancel the provisional reward. Also, please be considerate about disclosure when the bug affects a core library that may be used by other products. Please do NOT share this information with third parties who are not directly involved in fixing the bug. Doing so may cancel the provisional reward. Please be honest if you have already disclosed anything publicly or to third parties. Lastly, we understand that some of you are not interested in money. We offer the option to donate your reward to an eligible charity. If you prefer this option, let us know and we will also match your donation - subject to our discretion. Any rewards that are unclaimed after 12 months will be donated to a charity of our choosing.
*********************************
Nice one, ma7h1as.l@ - $1,000 for this report.
Labels: -reward-unpaid reward-inprocess
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 26

Labels: Merge-Request-71
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 26

Labels: -Merge-Request-71 Hotlist-Merge-Review Merge-Review-71
This bug requires manual review: M71 has already been promoted to the beta branch, so this requires manual review
Please contact the milestone owner if you have questions.
Owners: benmason@(Android), kariahda@(iOS), kbleicher@(ChromeOS), govind@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Hotlist-Merge-Review -Merge-Review-71
The CL already landed in M70 (71.0.3555.0), removing spurious merge bits.
Labels: Release-0-M71
Labels: CVE-2018-18353 CVE_description-missing
Labels: -CVE_description-missing CVE_description-submitted
Project Member

Comment 16 by sheriffbot@chromium.org, Dec 25

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment