Issue metadata
Sign in to add a comment
|
Security: Flash setting ignored
Reported by
aru....@gmail.com,
Jun 24 2017
|
||||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS There are sites where Flash settings are ignored. VERSION Chrome Version: [58.0.3029.110] + [stable] Operating System: [Windows 8.1 Pro] REPRODUCTION CASE Despite being set to [Allow sites to run Flash] and [Ask first] in Flash settings, Flash will be played without being asked. Example) https://abema.tv/now-on-air/new-anime
,
Jun 26 2017
Thanks for the report. This is working as intended for now due to Html5ByDefault, where if you use a site a lot, it will be permitted to run Flash without prompting. This is a compatibility measure since there are still a lot of heavily used sites which rely on Flash Over time, we are ramping up the usage threshold which a site has to meet in order to be permitted to run Flash without prompting the user. Eventually, running Flash will always prompt the user, but while we are transitioning, the two toggles in settings are slightly incongruous.
,
Jun 26 2017
Thanks for the answer. I understood it.
,
Oct 2 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by aru....@gmail.com
, Jun 24 2017