RTLO char allowed in chat
Medium
S
Snapchat
Submitted None
Actions:
Reported by
kontez
Vulnerability Details
Technical details and impact analysis
Hey all,
There seems to be no filtering of strange unicode characters such as U+202E which is an Right-To-Left-Override.
I can send messages like "Hey check out my new song at example.com/song[rtlo]3pm.exe" and everyone would see the link as "example.com/songexe.mp3".
Links that end with .exe are very suspicious but everyone would click on a link that ends with .mp3, filtering those characters would prevent clickjacking.
I tested this on the latest version of the Android App.
Thanks,
Marvin
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
UI Redressing (Clickjacking)