Executive brief
Chromedriver, a tool used to automate browser testing and control Google Chrome, downloads resources over unencrypted HTTP connections. An attacker with network access (such as on a corporate network or public Wi-Fi) can intercept and modify these downloads, potentially injecting malicious code that executes during testing or browser automation workflows.
Technical details
The vulnerability stems from the use of insecure HTTP (rather than HTTPS) to download binary resources required by chromedriver. An attacker in a privileged network position (on the same network segment, controlling a router, or performing DNS hijacking) can perform a man-in-the-middle (MITM) attack to intercept HTTP traffic. This allows the attacker to read or modify the downloaded resources, including the chromedriver binary itself, potentially leading to arbitrary code execution. The vulnerability affects all versions prior to 2.25.2; a fix is available in version 2.25.2 and later.
Affected products
- Google chromedriver all versions prior to 2.25.2
Timeline
- 2019-02-18: disclosed
- 2016: patched: Fix released in version 2.25.2