New issue
Advanced search Search tips

Issue 755486 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Aug 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

another fullscreen bad page not blocked by chrome

Reported by bau...@gmail.com, Aug 15 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.39 Safari/537.36

Steps to reproduce the problem:
1. open http://pc-error12.s3.amazonaws.com/33176542702/index.html

What is the expected behavior?
same as old version request user before enter fullscreen

What went wrong?
80% CPU usage, chrome not respond, black screen when use F11 to exit fullscreen and chrome not respond.
...

Did this work before? Yes when chrome request before enter fullscreen

Chrome version: 61.0.3163.39  Channel: beta
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version:
 

Comment 1 by bau...@gmail.com, Aug 15 2017

https://youtu.be/XXoj9KkzY-0  for screencast.
 same as previous report, this bad page for to fullscreen when clic.
But new: it hide mouse
if type F11 to exit fullscreen, chrome use 100% hang.. and must kill chrome tab process by windows taskmanager (I use 2 screens)
Components: UI>Browser>FullScreen
The change to HTML5 full-screen (allowed by default, hit ESC to exit) is working as intended. Hitting ESC exits full-screen mode, which is only entered after a user-action.

Closing this malicious page is easy in Chrome 62 on Mac.

I'll submit the target URL for blocking.
Status: Verified (was: Unconfirmed)
Thanks for the report! The site has been blocked by Safe Browsing.
Project Member

Comment 4 by sheriffbot@chromium.org, Aug 16 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify

Comment 5 by awhalley@google.com, Nov 14 2017

Labels: -Type-Bug-Security Type-Bug
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment