`CSP: sandbox; upgrade-insecure-requests` hits a null-deref. |
||
Issue descriptionIf a page is sandboxed into a unique origin, the current code which enforces upgrading insecure requests will end up doing dereferencing the origin's host. Unfortunately the origin has no host, and we end up doing a null-deref on the StringImpl. Whoops.
,
Sep 12 2016
|
||
►
Sign in to add a comment |
||
Comment 1 by bugdroid1@chromium.org
, Sep 1 2016