New issue
Advanced search Search tips

Issue 597546 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Security



Sign in to add a comment

Website able to open alert window that does not contain the Chrome logo

Reported by fer...@gmail.com, Mar 24 2016

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.87 Safari/537.36

Steps to reproduce the problem:
1. Visit this sketchy site (found in a popup ad) http://softnewready.preparedads.club/?pcl=wqKU72_baSVOty6BsI0-MvvM_NRYilapNgamSW5r4YY.&cid=63844750718&subid=106120&v_id=BavRznQdr9mjvZd41QhUWY_mQclxmI-f91UfOtKwsfI.

What is the expected behavior?
All alert windows should have the Chrome logo.

What went wrong?
Alert window opens that does not contain the Chrome logo. This should not be allowed.

Screenshot attached.

Did this work before? Yes All other alerts I've seen

Chrome version: 51.0.2689.0 canary (64-bit)  Channel: canary
OS Version: OS X 10.11.3
Flash Version: 21.0.0.204
 
Screen Shot 2016-03-24 at 2.38.57 AM.png
173 KB View Download

Comment 1 by rsesek@chromium.org, Mar 24 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
Alerts actually deliberately do not show the logo to make them look _less_ trusted, since they are created by the webpage, not Chrome. This was done in bug 584371.
Project Member

Comment 2 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment