Issue metadata
Sign in to add a comment
|
Security: Javascript Alert box dismissed when tabs switched
Reported by
freesix...@gmail.com,
Jul 13 2017
|
||||||||||||||||||||
Issue descriptionHi I’m Francis, My email is : freesix007@gmail.com or francis_ndangi@yahoo.fr I'm using Google Chrome "Version 59.0.3071.115 (Official Build) (64-bit)" which is up to date. and my small web application is this one (http://2time.co.za/sampleCalculator.html) I found a strange behaviour of Javascript “Alert” box in Google Chrome ONLY that can probably lead to security breach. When a Javascript dialog box is displayed on a Google Chrome page, if you browse/click on another tab and you come back on the page where the dialog box is displayed, the dialog box will disappear and will give you full access to the web page and this can probably lead to a security breach!!! I have my small web application for Budget Calculator (see link above) that pops up a Javascript dialog box after selecting the “Number of items” and click on “Create” button, And when you try to open another tab, or browse on another tab, and come back on my web application page(tab), the dialog box disappear and give you full access. You can simply use alter(“Hello World”); to test it on Google chrome, Firefox an Internet Explorer. It appears that ONLY on Google Chrome that the dialog box disappears after you click on anther tab, But on IE and FireFox even If you browse on another Tab and go back on that tab, the dialog box will always be displayed blocking you access. I also tried using below statement, only on Chrome that gives access after browsing on another tab. if (confirm("Press a button!") == true) { txt = "You pressed OK!"; } else { txt = "You pressed Cancel!"; } Kind Regards Francis Ndangi |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, Jul 13 2017Labels: -Restrict-View-SecurityTeam allpublic
Status: WontFix (was: Unconfirmed)
Summary: Security: Javascript Alert box dismissed when tabs switched (was: Security: Javascript Alert box)