Issue metadata
Sign in to add a comment
|
Security: Address spoofing when switching away from tab and back (repro Issue 648117)
Reported by
chromium...@gmail.com,
Nov 13 2017
|
||||||||||||||||||||||||
Issue descriptionVERSION Chrome Version: Chromium 64.0.3268.0 Operating System: Mac REPRODUCTION CASE I can repro this only on Chromium build. Apparently there is still something missing in issue 648117 .
,
Nov 13 2017
I can reproduce this sometimes on Mac Canary. kenrb, could you take a look please? Marking as Low severity since the spoofed content doesn't persist for more than a few seconds and it doesn't reproduce reliably.
,
Nov 13 2017
I can repro this reliably only on a trunk debug build not on Canary.
,
Nov 13 2017
#2: If it persists for no more than a few seconds then it is working as intended. There is a timer that clears the old page if the new one hasn't painted in sufficient time. I haven't been able to reproduce but the my trunk build on Mac is a few days old. Maybe there is a very recent regression here.
,
Nov 13 2017
On Canary it is working as intended (the spoof text persist only for 4 seconds), but on a trunk build doesn't work as intended. Sometimes looks like it can take several tries to repo, and sometimes it switches the origin tab automatically via alert() (as in the first comment #0) but if it doesn't, Try to switch it quickly and wait a few seconds then back to the popup tab to make it appear again.
,
Nov 13 2017
I still haven't been able to reproduce that, even after syncing and building again. Do you see anything different in the log output, between times when it successfully repros and times when it does not? It might be worth waiting to see if you can make it repro on tomorrow's Canary build, in case this is something very recently broken.
,
Nov 14 2017
,
Feb 14 2018
Are there any updates on the repro case for this one? Otherwise this seems like a candidate to Won'tFix
,
Feb 14 2018
No more of repro this bug. please close as WontFix.
,
Feb 14 2018
,
May 24 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by chromium...@gmail.com
, Nov 13 2017