New issue
Advanced search Search tips

Issue 685595 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 247535
Owner: ----
Closed: Jan 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 2
Type: Bug-Security



Sign in to add a comment

Do not copy text with zero size

Reported by c.adhit...@gmail.com, Jan 26 2017

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36

Steps to reproduce the problem:
1. Style an element's font size as 0px
2. Insert it between other visible text
3. Select and copy the entire thing - you'll see that the zero-size text is also copied.

Proof of concept: https://adtac.github.io/chrome-zero-size-text/index.html

What is the expected behavior?
This should not be the default behavior. Because a `display: none` style does not select the hidden text and this is similar to that.

What went wrong?
When the text is selected and copied, the zero-size text is copied too.

Proof of concept: https://adtac.github.io/chrome-zero-size-text/index.html

Did this work before? N/A 

Chrome version: 55.0.2883.87  Channel: stable
OS Version: Fedora 23
Flash Version: Shockwave Flash 24.0 r0
 
Components: Blink>Editing
Labels: OS-Chrome OS-Mac OS-Windows
Chrome's behavior matches IE, Edge, and Firefox. 

I don't think this is a security bug, and it seems like any change would be a breaking change to the web platform.

Comment 2 by mea...@chromium.org, Jan 26 2017

Labels: -Restrict-View-SecurityTeam allpublic
Mergedinto: 247535
Status: Duplicate (was: Unconfirmed)
This has been reported before, and our stance is that you should never paste untrusted text directly into the terminal. Please see  bug 247535  for more discussion.

Sign in to add a comment