There are several similar reports on chromium project. All of them are nofix.
Cursory hack – Fake address bar interaction
21–30 of 42 posts
Re: Cursory hack – Fake address bar interaction
#22Re: Cursory hack – Fake address bar interaction
#23Re: Cursory hack – Fake address bar interaction
#24Whoa that is a sweet hack. You should have submitted it to Google for a bug bounty. It should NOT be possible to clickjack the browser's address bar.
Re: Cursory hack – Fake address bar interaction
#25Re: Cursory hack – Fake address bar interaction
#26Re: Cursory hack – Fake address bar interaction
#27Re: Cursory hack – Fake address bar interaction
#28There are several similar reports on chromium project. All of them are nofix.
Really? That is strange, because there is ways this could be exploited... Can you link them to me?
Sorry, I'm on mobile. But several similar reports as the HN link shows.
Re: Cursory hack – Fake address bar interaction
#29Re: Cursory hack – Fake address bar interaction
#30So I thought this was just doing something on click (showing the fake HTTPS info), but that it maybe didn't work on newer or non-Chrome browsers, e.g. Chrome 52, Safari 9.1, and whatever bug was fixed there. But then I noticed that it causes really weird interactions at the top of the browser, at least on Mac; if you open the page in either Chrome or Safari and move your mouse towards the address bar, it jumps around…