Executive brief
Appium ChromeDriver is a testing automation tool that downloads browser components during operation. A vulnerability allows attackers positioned on the network to intercept and modify downloads over unencrypted HTTP connections, including the ChromeDriver binary itself. An attacker could inject malicious code into the binary, achieving remote code execution on any system using the affected tool.
Technical details
The vulnerability is a failure to use encrypted transport (CWE-311) when downloading resources, specifically the ChromeDriver binary and related dependencies. The affected versions download these resources over HTTP instead of HTTPS, making them susceptible to man-in-the-middle (MITM) attacks. An attacker with a privileged network position (e.g., on the same network or controlling network infrastructure) can intercept the download, modify the binary, and serve the malicious version to the victim. This requires no authentication or user interaction, though the attack does require network access between the victim and download server (AC:H reflects this constraint). Successful exploitation results in remote code execution when the compromised ChromeDriver binary is executed. Versions prior to 2.9.4 are affected; the fix enforces HTTPS for resource downloads.
Affected products
- Appium ChromeDriver < 2.9.4
Timeline
- 2019-02-18: disclosed: Published to GitHub Advisory Database
- 2019-02-18: patched: Fixed in version 2.9.4