Mojira Archive
MC-253441

Phishing attack possible with new chat reporting system

It is trivially possible to trick users into sending arbitrary messages that they did not type, which leads to their client signing that message, which means the message would be valid for reporting.

tellraw @a {"text":"Definitely an innocent link","underlined":true,"clickEvent":{"action":"run_command","value":"A very naughty message"}}

There is no warning or user indication as to what they are about to send to chat, making clicking on any chat dangerous.

Fixed

Earthcomputer

[Mojang] Gegy

2022-06-22, 09:18 AM

2022-06-23, 07:53 AM

2022-06-23, 07:53 AM

1

3

Confirmed

Very Important

Commands, Social Interactions

1.19.1 Pre-release 1

1.19.1 Release Candidate 1