New issue
Advanced search Search tips

Issue 686460 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: May 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Chrome will start downloading my files without waiting for my approval.

Reported by eumodssocial@gmail.com, Jan 28 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:51.0) Gecko/20100101 Firefox/51.0

Steps to reproduce the problem:
1.Select in settings "Ask where to save each file before downloading"
2.download any files but do not click save button in location selection window.
3.Wait some minute in this time chrome allready start your file but you didn't see. Probably save cache.
4.Than click save button and very huge files downloaded in only 1 sec. or moving cache folder too your selected location.

What is the expected behavior?

What went wrong?
Hello,

I just see today, In settings, I chose this "Ask where to save each file before downloading". But Chrome starting to download before I selecting the download location. When The green bar on the Chrome icon is full (Windows10), I click on the save button and then the huge file is being saved. That's it, it is already downloaded on the location selection screen. So, If it is an exe that is automatically downloaded by an infected site, It has already been downloaded. Sorry for my english. 

Have a nice day,
Joseph

Did this work before? N/A 

Chrome version: latest version - stabil  Channel: stable
OS Version: 10.0
Flash Version:
 

Comment 1 by est...@chromium.org, Jan 29 2017

 Issue 686505  has been merged into this issue.
Components: UI>Browser>Downloads
Labels: Security_Severity-Low Security_Impact-Stable
Owner: asanka@chromium.org
Status: Assigned (was: Unconfirmed)
I believe this is functioning as expected (Chrome begins buffering the download to a temporary location before knowing where the user wants to save it).

+asanka, can you elaborate on this?
Status: WontFix (was: Assigned)
#2 is correct. The resource contents start downloading immediately but the data is written to a temporary quarantined location until the user has confirmed the save operation. Until the download successfully completes, the file is not exposed on the filesystem under the final filename or file type.
Project Member

Comment 4 by sheriffbot@chromium.org, Aug 15 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment