Issue metadata
Sign in to add a comment
|
Security: SRI bypass by loading same resource twice in same origin on iOS
Reported by
chromium...@gmail.com,
Aug 24 2016
|
||||||||||||||||||||
Issue descriptionVERSION Chrome Version: 52.0.2743.84 Operating System: iOS REPRODUCTION CASE Note: Able to reproduce this issue only on iOS. PoC: https://heisenberg.co/sridemo/sameorigin/
,
Aug 24 2016
I'm pretty sure our SRI implementation is in Blink, so there might not be anything we can do on iOS other than report this to Apple (though we are still interested in these cases). That said, I don't really know what's involved here. jww: Anything we can do here?
,
Sep 1 2016
jww@ -- ping.
,
Sep 8 2016
Any updates on this bug?
,
Sep 8 2016
Hi, sorry, this came by while I was on vacation, and I completely missed it. Yes, mbarbella@'s comment is correct. SRI is inside of the web platform, and thus we don't control it on iOS, and in particular, it isn't implemented in WebKit, so it doesn't work in Chrome on iOS.
,
Sep 8 2016
,
Sep 8 2016
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by chromium...@gmail.com
, Aug 24 2016