New issue
Advanced search Search tips

Issue 682233 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 654140
Owner: ----
Closed: Jan 2017
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Force Fullscreen Javascript Loop

Reported by ronalddv...@gmail.com, Jan 18 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36

Steps to reproduce the problem:
Click anywhere on the white page when you open the "index.html" after that chrome will be forced to fullscreen. If you try to press "ESC" the chrome will go instantly back to fullscreen.

What is the expected behavior?
Chrome is stuck in a full screen mode.

What went wrong?
There should be a protection how many times "Fullscreen" can be triggered in some time limit.

Did this work before? N/A 

Chrome version: 55.0.2883.87  Channel: stable
OS Version: 10.0
Flash Version: Shockwave Flash 24.0 r0

Here is a video about the vulnerability: https://www.youtube.com/watch?v=L6Xr2wfxm4c

I consider this is a very high threat vulnerability as you can take control of someone else's browser.
 
index.html
2.1 KB View Download
Mergedinto: 654140
Status: Duplicate (was: Unconfirmed)
Sounds like  Issue 654140  initially fixed in 56.0.2915.0
Project Member

Comment 2 by sheriffbot@chromium.org, Apr 27 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment