Crash Google Chrome with one tiny URL: We cram a probe in this bug

Christian Berger Silver badge

Why does it even unescape that string?

I mean the URL will be sent verbatim to the server just as it's entered and stored everywhere. There is no reason to turn %20 into a space or anything, let alone doing this multiple times. There may be reasons to do the opposite, for example on forms, but unescaping a string should never be done by the user agent.

