New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 612939 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Away
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 0
Type: Bug-Security



Sign in to add a comment

Security: Wrong origin security indicators in Chrome Custom Tab

Project Member Reported by palmer@chromium.org, May 18 2016

Issue description

See screenshots: An HTTP page-load gets the green lock, for some reason.

 

Comment 1 by palmer@chromium.org, May 18 2016

Here are the screenshots.
Screenshot_20160512-211259.png
266 KB View Download
Screenshot_20160512-211304.png
162 KB View Download

Comment 2 by palmer@chromium.org, May 18 2016

Cc: nparker@chromium.org
Was this in a particular app/OS version? I wasn't able to reproduce on my Nexus7 device.

Comment 4 by palmer@chromium.org, May 18 2016

Using the Twitter app on Nexus 5, Android version 6.0.1, Chrome 50.0.2661.89.

I am now seeing the behavior that nparker reported, where the green lock shows for 1 second and then goes away.
Project Member

Comment 5 by sheriffbot@chromium.org, May 19 2016

Labels: Pri-1
Cc: ian...@chromium.org
Labels: -Security_Severity-Medium Security_Severity-High
Owner: yus...@chromium.org
Status: Assigned (was: Available)
I can absolutely totally reproduce by searching for "abc7news" on Twitter and clicking on the the first tweet I see (on a Nexus 5X). Since even savvy users can't tell that the lock icon is wrong, I believe this absolutely qualifies for high severity.

yusufo@, you handled  Issue 525150  and related bugs; could you look into this as soon as you can?

Comment 7 by yus...@chromium.org, May 19 2016

Cc: -ian...@chromium.org yus...@chromium.org
Labels: ReleaseBlock-Dev
Owner: ian...@chromium.org

Comment 8 by palmer@chromium.org, May 19 2016

Labels: -Security_Severity-High Security_Severity-Medium
I don't think this meets the definition of High, given in https://www.chromium.org/developers/severity-guidelines. It's not e.g. a UXSS. I'd call it Medium at most; I even debated calling it Low when I filed it.
Labels: -ReleaseBlock-Dev ReleaseBlock-Stable
Updating RB-Dev to RB-Stable given c#8, please correct if you have any concerns.  That said we should fix ASAP.
Status: Started (was: Assigned)
Basically https://t.co/lPI8tRXnoD will trigger this bug in CCT's toolbar UI.

Comment 11 by kenrb@chromium.org, May 26 2016

ianwen@: Have you diagnosed the cause at all? Does this look feasible to fix quickly?
Yes. The cause is that the icon animations happen too quickly one after the other.

It is trivial to fix it. I already have a CL (~10 lines of code) and will merge it to M52.

Comment 13 by aarya@google.com, May 27 2016

Once your fix is checked in, please mark bug as fixed, and ClusterFuzz should add the merge triage labels later. Merge can come later, but lets get the fix in this week (since we are in security fixit this week).

Comment 14 by kenrb@chromium.org, May 31 2016

ianwen@: Is there an ETA for that patch?
Labels: -Pri-1 Pri-0
Today or tomorrow.
Project Member

Comment 16 by bugdroid1@chromium.org, May 31 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/ba21bb8491e53472c1878e8af4f8c2aab18ce336

commit ba21bb8491e53472c1878e8af4f8c2aab18ce336
Author: ianwen <ianwen@chromium.org>
Date: Tue May 31 22:37:55 2016

[Custom Tabs] Fix a bug that security icon might show for http

If the security icon state changes faster than the time it takes for
Android to relayout, hide animation might be called even before the
security icon's visibility has been flipped. This CL fixes the bug in
this scenario.

BUG= 612939 

Review-Url: https://codereview.chromium.org/2024173003
Cr-Commit-Position: refs/heads/master@{#396957}

[modify] https://crrev.com/ba21bb8491e53472c1878e8af4f8c2aab18ce336/chrome/android/java/src/org/chromium/chrome/browser/toolbar/CustomTabToolbarAnimationDelegate.java

Project Member

Comment 17 by bugdroid1@chromium.org, Jun 1 2016

Labels: merge-merged-2743
The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/4376e086baffb084b6e5fe02e011fbe466bc1853

commit 4376e086baffb084b6e5fe02e011fbe466bc1853
Author: Ian Wen <ianwen@google.com>
Date: Wed Jun 01 18:41:03 2016

[Custom Tabs] Fix a bug that security icon might show for http

If the security icon state changes faster than the time it takes for
Android to relayout, hide animation might be called even before the
security icon's visibility has been flipped. This CL fixes the bug in
this scenario.

BUG= 612939 

Review-Url: https://codereview.chromium.org/2024173003
Cr-Commit-Position: refs/heads/master@{#396957}
TBR=yusufo@chromium.org

Review URL: https://codereview.chromium.org/2027843003 .

Cr-Commit-Position: refs/branch-heads/2743@{#169}
Cr-Branched-From: 2b3ae3b8090361f8af5a611712fc1a5ab2de53cb-refs/heads/master@{#394939}

[modify] https://crrev.com/4376e086baffb084b6e5fe02e011fbe466bc1853/chrome/android/java/src/org/chromium/chrome/browser/toolbar/CustomTabToolbarAnimationDelegate.java

Status: Fixed (was: Started)
Fixed in M53 and merged to M52. Please verify.
Project Member

Comment 19 by sheriffbot@chromium.org, Jun 1 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Cc: -nparker@chromium.org
Labels: Release-0-M52
Project Member

Comment 22 by sheriffbot@chromium.org, Sep 8 2016

Labels: -Restrict-View-SecurityNotify
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 23 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 24 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic
Components: -Security>UX
Labels: Team-Security-UX
Security>UX component is deprecated in favor of the Team-Security-UX label

Sign in to add a comment