Author Topic: 16 chars that can crash your chrome browser!  (Read 6125 times)

0 Members and 1 Guest are viewing this topic.

Offline TeaNTronicsTopic starter

  • Contributor
  • Posts: 10
16 chars that can crash your chrome browser!
« on: September 21, 2015, 11:28:04 am »
i found some chrome bug on the web.
there is a new bug in google chrome that can crash your browser.
if you moving your mouse over this link (or long-pressing on mobile), or trying to open the link,
it will cause your browser to crash. i have tested this, it works.
here is the link (don't say i didn't warn you):

Code: [Select]
http://a/%%30%30

you can find more details about it here: http://www.theregister.co.uk/2015/09/20/chrome_url_crash/
there is also an bug issue on chromium: https://code.google.com/p/chromium/issues/detail?id=533361



edit: i had to put it on code quote so it won't crash your browser when you view it :palm:
« Last Edit: September 21, 2015, 11:55:47 am by TeaNTronics »
 

Offline zapta

  • Super Contributor
  • ***
  • Posts: 6289
  • Country: 00
Re: 16 chars that can crash your chrome browser!
« Reply #1 on: September 21, 2015, 11:58:17 am »
It crashed mine. Good catch.
 

Offline Rerouter

  • Super Contributor
  • ***
  • Posts: 4700
  • Country: au
  • Question Everything... Except This Statement
Re: 16 chars that can crash your chrome browser!
« Reply #2 on: September 21, 2015, 12:35:45 pm »
How does someone find a bug like this?
 

Offline krivx

  • Frequent Contributor
  • **
  • Posts: 765
  • Country: ie
Re: 16 chars that can crash your chrome browser!
« Reply #3 on: September 21, 2015, 12:44:44 pm »
If this is yours I would submit it to the bounty program: https://www.google.com/about/appsecurity/chrome-rewards/
 

Offline PA0PBZ

  • Super Contributor
  • ***
  • Posts: 5189
  • Country: nl
Keyboard error: Press F1 to continue.
 

Offline TeaNTronicsTopic starter

  • Contributor
  • Posts: 10
Re: 16 chars that can crash your chrome browser!
« Reply #5 on: September 21, 2015, 12:53:49 pm »
How does someone find a bug like this?

i guess he just bump into it

If this is yours I would submit it to the bounty program: https://www.google.com/about/appsecurity/chrome-rewards/

i'm not the person who found this bug first, the person who found it is a bloger called Andris Atteka:
http://andrisatteka.blogspot.nl/2015/09/a-simple-string-to-crash-google-chrome.html

and he already filled a bug report at chromium:
https://code.google.com/p/chromium/issues/detail?id=533361

and he tried to submit the report to the reward program, but he got nothing:
Quote
Unfortunately no reward was awarded as this was deemed to be only a DOS vulnerability.
Anyway, making secure software is much harder than finding issues in it.
Thanks Google.
« Last Edit: September 21, 2015, 01:07:45 pm by TeaNTronics »
 

Offline TeaNTronicsTopic starter

  • Contributor
  • Posts: 10
Re: 16 chars that can crash your chrome browser!
« Reply #6 on: September 21, 2015, 01:08:39 pm »
 

Offline Jeroen3

  • Super Contributor
  • ***
  • Posts: 4150
  • Country: nl
  • Embedded Engineer
    • jeroen3.nl
Re: 16 chars that can crash your chrome browser!
« Reply #7 on: September 21, 2015, 01:23:16 pm »
The link posted by TeaNTronics does not cause a crash. But it does if you add two more 'a' characters.
The mouseover in the bug report crashes all the tabs, but a navigating to the link crashes the entire browser.
Chrome Windows 45.0.2454.93 m
 

Offline G7PSK

  • Super Contributor
  • ***
  • Posts: 3865
  • Country: gb
  • It is hot until proved not.
Re: 16 chars that can crash your chrome browser!
« Reply #8 on: September 21, 2015, 01:58:16 pm »
It crashes Opera as well as Chrome but unlike chrome opera bounces straight back up again.
 

Offline Jeroen3

  • Super Contributor
  • ***
  • Posts: 4150
  • Country: nl
  • Embedded Engineer
    • jeroen3.nl
Re: 16 chars that can crash your chrome browser!
« Reply #9 on: September 21, 2015, 04:53:11 pm »
Well, opera uses the same engine on a different shell. Not that surprising.
 

Offline JacquesBBB

  • Frequent Contributor
  • **
  • Posts: 829
  • Country: fr
Re: 16 chars that can crash your chrome browser!
« Reply #10 on: September 21, 2015, 05:53:19 pm »
It does not crash Safari.
 

Offline zapta

  • Super Contributor
  • ***
  • Posts: 6289
  • Country: 00
Re: 16 chars that can crash your chrome browser!
« Reply #11 on: September 21, 2015, 06:51:09 pm »
Any guess what is special about this string?
 

Offline Bud

  • Super Contributor
  • ***
  • Posts: 7078
  • Country: ca
Re: 16 chars that can crash your chrome browser!
« Reply #12 on: September 21, 2015, 07:15:03 pm »
Try converting to Windings
Facebook-free life and Rigol-free shack.
 

Offline Halcyon

  • Global Moderator
  • *****
  • Posts: 5880
  • Country: au
Re: 16 chars that can crash your chrome browser!
« Reply #13 on: September 21, 2015, 08:24:42 pm »
Tried it in Chrome 43.0.2357.134 m -- It did nothing.
 

Offline crispy_tofu

  • Super Contributor
  • ***
  • Posts: 1124
  • Country: au
Re: 16 chars that can crash your chrome browser!
« Reply #14 on: September 22, 2015, 02:23:04 am »
Works on Chrome OS 46.0.2490.33 beta... it blanks the screen and recovers after a few seconds.  :o
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf