New issue
Advanced search Search tips

Issue 766764 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 727076
Owner: ----
Closed: Sep 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Textarea and Text input field can hide submitted content under MacOS

Reported by fosspr...@gmail.com, Sep 19 2017

Issue description

VULNERABILITY DETAILS
Chrome may hide critical user input causing errors and potential unintended disclosure on nested CSS grids with text or textarea inputs.

VERSION
Chrome Version: Chrome/61.0.3163.91 stable
Operating System: Mac OSX 10_12_5

REPRODUCTION CASE
https://s.codepen.io/fossprime/debug/jGqqXN/yYAyLDzQegzr
 
Labels: Needs-Feedback
Can you please explain in detail what security problem you believe you've identified here? 

HTML and CSS can style input controls in myriad ways, including those that render them effectively invisible. That does not itself represent a security vulnerability.

Comment 2 by palmer@chromium.org, Sep 19 2017

The codepen link says "This debug view expired.". Could you please attach a proof of concept to this bug? Thanks.

Comment 3 by fosspr...@gmail.com, Sep 19 2017

If a developer uses safari and tests Chrome on linux... it could be the case that users end up pasting confidential info and submitting it to someone unintentionally.

The source of the issue is probably the same as the textarea issue
https://bugs.chromium.org/p/chromium/issues/detail?id=727076

I've attached a local file that still has the problem
CodePen - Form Layout #1_ CSS Grid.htm
1.3 KB View Download
Project Member

Comment 4 by sheriffbot@chromium.org, Sep 19 2017

Cc: elawrence@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
This doesn't sound like a security issue; there's nothing that would lead a user to "paste confidential information" into this page, and upon any sort of paste, the page has full access to the clipboard's text, whether it's visible or not.

I'm not able to reproduce any functional problems here either (but it sounds like you're saying that maybe this only has a problem on one platform)? Can you explain what exactly the functional problem is?
Mergedinto: 727076
Status: Duplicate (was: Unconfirmed)
Ah, yes, this is the same as  Issue 727076 
Labels: -Restrict-View-SecurityTeam allpublic

Sign in to add a comment