Google was the first vendor I contacted regarding this. After initially recieving a SEC-MEDIUM rating, it was later changed to SEC-LOW and ignored for months (~6). It turned out that Chrome would be able to detect this type of bug if anyone would try to use it on a mass scale, as it is logged by browser safety.
I'm still confused by this, but I believe what they mean is that they can both detect and block any malicious website that shows sudden high usage of the folder uploader. The same PoC reported to Microsoft works on Chrome as of writing this on 4/13/2017.
The worst part is that if the filepicker was defaulted to 'C:\', you would be able to read the entire disk..because the folder picker uploads all files within all sub directories.
暂无评论