Status: Assigned
issue 739672

Ignore <a download> for cross origin URLs
Project Member Reported by, Apr 22
To avoid what is essentially  user-mediated cross-origin information leakage, Blink will start to ignore the presence of the download attribute on anchor elements with cross origin attributes.

* HTMLAnchorElement


Internet Explorer: different mitigation
Firefox: shipped
Safari: shipped

commit 99a1d0db25c2b77ad42d216b2289e0bf67c69540
Author: Jochen Eisinger <>
Date: Fri May 26 14:16:45 2017

cross origin downloads w/o content disposition are dangerous


Change-Id: I170ad3a3bec4afe64897a16c98c25e8a152c15ed
Commit-Queue: Jochen Eisinger <>
Reviewed-by: David Trainor <>
Cr-Commit-Position: refs/heads/master@{#475000}

Status: Fixed
Status: Assigned
#1 - this might have caused  issue 730050  (downloaded data URLs do not get their file name from the download attribute).
Blockedon: 739672
