New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 631814 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Last visit > 30 days ago
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

unUnload and beforeUnload Javascript events enable malicious site actions, should be completely disabled permanently

Reported by anonymou...@gmail.com, Jul 26 2016

Issue description

What steps will reproduce the problem?
(1) Start filling out a form on any page
(2) Attempt to navigate away from page
(3) "Are you sure you want to leave this page?" popup appears

What is the expected result?

I should be able to navigate to any page I want without the PERMISSION of the owners of the domain I'm currently looking at. When I click to navigate away, any action other than NAVIGATING AWAY is against my wishes and a malicious action against me.

What happens instead?

A popup appeared preventing me from navigating away until I click on it. This is not the desired action.


Please provide any additional information below. Attach a screenshot if
possible.

 
Cc: tkonch...@chromium.org
Labels: Needs-Feedback
Unable to reproduce the issue on mac 10.11.5 chrome version 52.0.2743.82 and canary 54.0.2809.0 using the sample form https://www.eply.com/conference-form-sample - After step2 did not observe any popup

Could you please provide the sample form where you are facing the issue and also the OS details for further investigation.


Components: Internals
Components: -Internals UI>Browser>Navigation
Showing a prompt is Working-as-Intended; if the LEAVE button does not work, that's potentially a bug.
Components: -UI>Browser>Navigation UI>Browser>TabContents
No. When I click the "back" button or a link, "showing a prompt" is NOT the intended action. Letting a site prevent me from leaving by nagging me with a "prompt" is spam, and it's a possible attack vector too. When I click a link it should go to the URL, not go to a prompt. That is NOT the intended action. It's not working, it's a bug and it's an attack.
Project Member

Comment 6 by sheriffbot@chromium.org, Sep 23 2016

Labels: -Needs-Feedback Needs-Review
Owner: tkonch...@chromium.org
Thank you for providing more feedback. Adding requester "tkonchada@chromium.org" for another review and adding "Needs-Review" label for tracking.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 7 by a...@chromium.org, Dec 7 2016

Status: WontFix (was: Unconfirmed)
Sorry, we're keeping onbeforeunload.

Sign in to add a comment