New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 619437 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 619429
Owner: ----
Closed: Jun 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Users can accidentally grant access to webcam/microphone

Reported by studioso...@gmail.com, Jun 13 2016

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs


VULNERABILITY DETAILS
The popup for granting access to webcam/microphone has the "Allow" button on focus by default. Websites can get access users webcam/microphone without their permission by having users press the spacebar button in search bars. Reproduction linked below. This security flaw can be resolved by removing the autofocus on the popup.

VERSION
Chrome Version: 51.0.2704.79 (64-bit) + stable-channel parrot
Operating System: Chrome OS (Chromebook) 8172.47.0 (Official Build)

REPRODUCTION CASE
https://jsfiddle.net/v8269bcm/

 
Cc: raymes@chromium.org
I can't repro on linux.  Is this only on chromeos?

raymes -- Can you take a look?

Comment 2 by raymes@chromium.org, Jun 13 2016

Mergedinto: 619429
Status: Duplicate (was: Unconfirmed)

Comment 3 by f...@chromium.org, Jun 13 2016

Thank you for the detailed report, we are handling this as a security vulnerability in another bug ID.
Labels: allpublic
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 12 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment