New issue
Advanced search Search tips

Issue 908258 link

Starred by 1 user

Issue metadata

Status: Unconfirmed
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug



Sign in to add a comment

Security: Expensive animation call makes DOS on all chrome tabs window

Reported by cs.anura...@gmail.com, Nov 25

Issue description

While navigating on one of the website, I observed that heavy animation causes chrome to turn full chrome window black. This leaves users no choice but to close the window and hence lose their work.

Steps:

1. Navigate to https://about.hrdatabank.com
2. Site uses Revolution slider plugin using expensive animation
3. Wait for some time until animation tries to flip the image
4. Once the animation tries to run, full chrome window turns black.
5. User now have no choice but to close chrome and lose their work

This problem can only be removed by disabling hardware acceleration but that also causes the tab to freeze or respond very slow
 
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Though this is potentially still a bug, we don't treat denial of service issues as security vulnerabilities. Removing security flags and view restrictions.

See https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Are-denial-of-service-issues-considered-security-bugs for more information.
Labels: Needs-Milestone
Cc: swarnasree.mukkala@chromium.org
Components: UI
Labels: Needs-Feedback Triaged-ET
Tried testing the issue on latest stable #70.0.3538.110 using Ubuntu 17.10 by following below steps.

Steps:
=====
1.Launched chrome.
2.Hardware acceleration is enabled under "chrome://settings".
3.Navigated to "https://about.hrdatabank.com".
4.Observed that when the animation is being played, after the image got flip did not observe chrome window turning into black.

Attached screencast for reference.
@reporter: Could you please review attached screencast and let us know if anything is being missed here. Requesting you to provide the chrome version by navigating to "chrome://version" and OS details, so that it would be really helpful for further triaging of the issue.
Thanks.!
908258.webm
10.7 MB View Download
Labels: Pri-2
Issue has a component, but no priority. Updating to have default priority (Pri-2)

Sign in to add a comment