New issue
Advanced search Search tips

Issue 654788 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Oct 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: ----



Sign in to add a comment

Window title contains page title text from incognito mode tab

Reported by juho.tyk...@gmail.com, Oct 11 2016

Issue description

PRIVACY ISSUE
Window title contains page title text from incognito mode tab and that is obtainable with different ways from 3rd party applications or operating system itself.

VERSION:
Chromium Version: Chromium 53.0.2785.143 stable
Operating System: Debian GNU/Linux 8.6 kernel 3.16.0-4-amd64

REPRODUCTION STEPS (Linux, X.org)
Install and run xdotool to obtain active window name. Make it run every 2 seconds (watch's default):

$ watch xdotool getactivewindow getwindowname

Start Chromium and open incognito mode and resize browser window to smaller size so you can see terminal (watch output) and browser at a same time.

Browse to some veiled site and see window title in terminal.

REPRODUCTION STEPS (Windows 7+)
https://code.msdn.microsoft.com/windowsapps/How-to-get-the-title-of-4ec7f32f
 
Components: UI>Browser>Incognito
I believe this is working-as-intended. Locally running software can inspect many aspects of an Incognito instance, taking its screenshots, etc.

One could consider masking the window title in Incognito mode (so that it doesn't appear on the Windows taskbar, etc) but this would have a significant impact on the usability of the browser.


Comment 2 by battre@chromium.org, Oct 12 2016

Status: WontFix (was: Untriaged)
I agree:
https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-

Also you could still capture the title and content of the incognito mode window, capture URLs, etc.

Sign in to add a comment