invalid homepage URL causes 'uncaught typeerror' or blank state
Low
B
Brave Software
Submitted None
Actions:
Reported by
tsug0d
Vulnerability Details
Technical details and impact analysis
## Summary:
The issue is when you set the homepage as https://brave.com;https://google.com.vn and then change the setting to launch brave with homepage
## Products affected:
Tested on windows7 x64 + BraveSetup-ia32
## Steps To Reproduce:
1.go to Settings -> General, inject to "My home page is": https://brave.com;https://google.com.vn
2. close browser and reopen it
3. The browser become blank (forever?)
I try to unistall and reinstall brave but this issue still happen, so i have to go to my virtual machine to test it again.
If the attacker can trick user to change their homepage using this payload, they can shutdown user's browser (forever?)
we can set homepage by javascript, and trick user to click this button, attacker can build those script too.
or simply told victim to set their homepage to "https://brave.com;https://google.com.vn" to see some fun.
## PoC:
https://cloud.githubusercontent.com/assets/17010094/19560362/d31ad10c-96f1-11e6-8895-161a6018e056.gif
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Violation of Secure Design Principles