PDF files in Chrome for Android still download after clicking cancel on "external program" dialog in incognito mode
Reported by
resea...@nightwatchcybersecurity.com,
May 25 2016
|
||||||||
Issue descriptionVULNERABILITY DETAILS When using Chrome in incognito mode, and hitting a PDF file, a warning about external program comes up. Click on "cancel" still downloads the file. VERSION Chrome Version: 50.0.2661.89 Operating System: Android 6.0, Patch level January 1, 2016 REPRODUCTION CASE 1. Go into incognito mode. 2. Search for "irs pdf 1040". 3. Click on result. 4. Click on cancel on "external warning" dialog. 5. Observe the file download anyway.
,
May 27 2016
I agree in the sense that Chrome is very explicit about files downloaded in incognito mode stay on your disk. However, I tried this out and observed that the download is triggered AFTER the user has pressed cancel. This is indeed surprising.
,
May 27 2016
Our report is specifically about the fact that hitting the cancel button still downloads.
,
May 27 2016
Happy to reopen the bug, but it seems to me that downloading the file after clicking cancel doesn't have any security or privacy implications, but rather a functional issue. I'm hesitant to say downloading the file is a bug though. I can imagine users would be confused if they click on a pdf, say "no" to open the pdf in an external dialog and then end up with Chrome doing nothing, assuming they intended to download the pdf in the first place. Does this only happen with pdf files?
,
May 27 2016
Yes. We tested with other file types and it only happens with PDFs. Maybe some sort of carryover from the desktop browser which has a built-in PDF viewer while android does not?
,
May 27 2016
Thanks, I'm not sure about the reason either. +tedchoc from bug 587306
,
May 27 2016
</bad attempt at renaming the bug>
,
May 29 2016
The source of this problem is in: https://chromium.googlesource.com/chromium/src.git/+/master/chrome/android/java/src/org/chromium/chrome/browser/externalnav/ExternalNavigationDelegateImpl.java Specifically, the intent gets overriden for PDF files.
,
May 30 2016
I kind of sympathize with comment 4. If the behavior was changed, there was no way to download a PDF file in incognito mode, right?
,
May 31 2016
Adding qinmin@ for downloads. I think it is very similar to the bug linked in #6. The dialog is just confusing, but it is specifically about launching external applications. If you click on a link to maps.google.com, you get warned that you're about to leave chrome for another application. If you hit cancel, you are still navigated to the webpage. I would argue that that experience is just as odd as the one described here. One is a download action one is a navigation action. Both do "something" on cancel.
,
May 31 2016
Maybe cancelling the app chooser dialog should be considered as cancelling the navigation? But then user has to always choose "chrome" from the app chooser if we really want the navigation to continue.
,
May 31 2016
@#11, that was actually the previous behavior. I like that there is an option to stay in chrome, but the wording is IMO confusing. If I recall, no one could come up with a concise language for the action that would proceed in Chrome, so we stuck with Cancel. "Continue in Chrome" or "Stay in Chrome" are both quite lengthy. Until there is an outcome on crbug.com/587306 , then I think we should hold off on anything.
,
Mar 9 2017
,
Apr 13 2018
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue. Sorry for the inconvenience if the bug really should have been left as Available. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Apr 13 2018
Can't reproduce. I don't see an external program warning. |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by mea...@chromium.org
, May 25 2016Components: UI>Browser>Incognito Privacy
Labels: OS-Android
Status: WontFix (was: Unconfirmed)