New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 782951 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 2
Type: Bug



Sign in to add a comment

Removal of blacklisted extension still opens uninstall URL

Project Member Reported by nrpeter@chromium.org, Nov 8 2017

Issue description

Chrome Version: 62.0.3202.89
OS: macOS 10.12.6
Found by: vdedhia@

What steps will reproduce the problem?
(1) Install an extension that runs chrome.runtime.setUninstallURL()
(2) Blacklist the extension with ExtensionInstallBlacklist
(3) Remove the extension from chrome://extensions 

What is the expected result?
The uninstall URL isn't opened

What happens instead?
A new tab is opened and navigates to the uninstall URL

Concern:
If an extension has been added to the blacklist, it may be malware. Allowing the extension to open a URL of its choice on removal could put the user at risk.

 
Components: UI>Browser>ExtensionsManagement
Labels: Needs-Triage-M62 Needs-Bisect
Cc: rdevlin....@chromium.org
Owner: catmulli...@chromium.org
Status: Assigned (was: Untriaged)
Heh, yeah, that's bad.  We should fix that.

catmullings@, think this is something you could tackle?
Is there any additional information we could provide that would help in fixing this?
Thanks for the ping nrpeter@. No add'l info needed. I have started implementing a fix for this.
Project Member

Comment 6 by bugdroid1@chromium.org, Dec 9 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/e81f74c848669929cefd25c6ec199da00f331779

commit e81f74c848669929cefd25c6ec199da00f331779
Author: Catherine Mullings <catmullings@chromium.org>
Date: Sat Dec 09 00:06:03 2017

Extensions: Do not open uninstall url for blacklisted extensions

Bug:  782951 
Change-Id: I6a56cd27f51f99a3422fbbf145a0d4f9246fc44e
Reviewed-on: https://chromium-review.googlesource.com/816056
Commit-Queue: catmullings <catmullings@chromium.org>
Reviewed-by: Istiaque Ahmed <lazyboy@chromium.org>
Cr-Commit-Position: refs/heads/master@{#522929}
[modify] https://crrev.com/e81f74c848669929cefd25c6ec199da00f331779/extensions/browser/api/runtime/runtime_api.cc
[modify] https://crrev.com/e81f74c848669929cefd25c6ec199da00f331779/extensions/browser/api/runtime/runtime_apitest.cc

Status: Fixed (was: Assigned)

Sign in to add a comment