New issue
Advanced search Search tips

Issue 746462 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jul 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: ----
Type: Bug-Security

Blocked on:
issue 739091



Sign in to add a comment

Security: Mac-only form field validation bubbles can appear after navigating to another origin

Reported by chromium...@gmail.com, Jul 19 2017

Issue description

VERSION
Chrome Version: 61.0.3159.0 (Official Build) canary (64-bit)
Operating System: Mac

See  issue 673163  and  issue 704560  

REPRODUCTION CASE
1. Open the test case.
2. Keep clicking on the button.
3. After two seconds, observe the field validation bubble can appears after navigating to google.com.

Note: I couldn't repro this on Windows and Linux.

 
Field validation bubble.html
1.0 KB View Download
Actual.mov
1.5 MB Download
Components: Blink>Forms>Validation
Labels: OS-Mac
Labels: Needs-Feedback
I cannot reproduce this, but I looked at the video. Why do you feel this is a security bug and not a general purpose bug?
This is a hypothetical attack, evil.com can open an OAuth page and display a "You should click accept" dialog on that tab, which would be bad.

I think this is medium as  issue 713686  based on  https://crbug.com/673163#c19  
Project Member

Comment 4 by sheriffbot@chromium.org, Jul 19 2017

Cc: kerrnel@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "kerrnel@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Owner: tkent@chromium.org
Status: Available (was: Unconfirmed)
tkent@, since you handled 713686 can you look at this and let me know what you think?

Comment 6 by tkent@chromium.org, Jul 19 2017

Blockedon: 739091
Status: WontFix (was: Available)
I reproduced this, and confirmed this was already fixed if we enabled chrome://flags/#enable-experimental-web-platform-features . 
We're going to enable the flag for new implementation soon.

Project Member

Comment 7 by sheriffbot@chromium.org, Oct 26 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment