window.alert can DOS browser

Originator:callum
Number:rdar://21193770 Date Originated:
Status:Open Resolved:
Product:Safari Product Version:
Classification: Reproducible:
 
Callum Jones01-Jun-2015 05:17 PM

Summary:
Visit http://mac-securities.com/y/index12.html

This website spams window.alert and the only way to resolve this is to Force Quit Safari. Other browsers like Chrome and Firefox allow you to end the alert if it appears multiple times.

Despite the multi process model and killing the tab, Safari just reloads it and the alerts appear again.

Steps to Reproduce:
Visit http://mac-securities.com/y/index12.html
Try to click OK

Expected Results:
Safari should be smart and detect window.alert spam OR allow control of the browser.

Actual Results:
Safari is stuck in a alert loop.

Version:
OS X Yosemite

Notes:


Configuration:
Out of the box Safari

Attachments:

Comments


Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!