Warn media middle-clicking
Middle-clicking graphical media (e.g. GIF) takes the user to the origin of the media.
My friend found a vulnerability from this feature. The following gif will display the gif only if the requester is Discord client but redirects to an arbitrary malware site with other requests, i.e. user middle-clicks the GIF in Discord (they see a playing GIF), but the browser takes them to an arbitrary site without any warning whatsoever. You can try it out with this one: https://mislead.skidiot.club/example.gif
Source code here: https://github.com/Vsimpro/misdirection
This is Discord's response to my security report:
I understand you would like to report malicious links sent in the form of GIFs that do not ask for confirmation when middle clicking them, and instead open them right away.
This is currently working as intended. If you would like to see changes made to our app in the future, you can post and/or upvote the idea.
I would like a warning from clicking media sources as well, not just for regular URLs.
Accedi per aggiungere un commento.
Commenti
0 commenti