New issue
Advanced search Search tips

Issue 904399 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner:
Closed: Nov 13
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: Unknown crash on macOS

Reported by chromium...@gmail.com, Nov 12

Issue description


VERSION
Chrome Version: 72.0.3608.0 (Official Build) canary (64-bit)
Operating System: Mac 10.12.6 

REPRODUCTION CASE
1. Visit chromium.org 
2. Visit https://lbherrera.github.io/lab/204spoof.html
3. Click on CMD + left click three times 
4. Click on back icon

Crash/ece1dff14269183f
Crash/4d003c6c37d13843

I'm actually not sure about if this is a security crash. Could someone share with us the call traces by crash IDs.
 
screen.mov
2.6 MB View Download
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Owner: dcheng@chromium.org
Status: Assigned (was: Unconfirmed)
Thanks for the report. This isn't a security issue, it hits a CHECK in Page::RequestBeginMainFrameNotExpected().

dcheng@: Do you think this is the same as issue 838348? Please dupe if so.
Cc: dcheng@chromium.org
Owner: danakj@chromium.org
One of the crashes is indeed RequestBeginMainFrameNotExpected; however the other crash (https://crash.corp.google.com/browse?q=reportid=%274d003c6c37d13843%27) is a null deref in GetURLForDebugTrace(). danakj@ did some cleanup in this area recently, so assigning to confirm whether or not that particular crash is addressed yet.
Cc: enne@chromium.org
It should be. https://bugs.chromium.org/p/chromium/issues/detail?id=896836

I had a quick fix that merged out to stable, and a longer term fix just landed the other week. If there are more ways to get there then maybe I reintroduced it.
Mergedinto: 896836
Status: Duplicate (was: Assigned)
That crash is at 607123 which is after the last CL so I guess it's back sigh.

Sign in to add a comment