New issue
Advanced search Search tips

Issue 795477 link

Starred by 3 users

Issue metadata

Status: Unconfirmed
Owner: ----
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug



Sign in to add a comment

In a GoGuardian & policy restricted ChromeOS Chromebook, the incognito mode can still be accessed through a chrome://inspect exploit.

Reported by jeremyeb...@gmail.com, Dec 16 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36
Platform: 64.0.3282.24

Steps to reproduce the problem:
Go to chrome://inspect/#other.
Find chrome://oobe/lock
Click on "inspect" and navigate to "application" on the top bar.
Click on "read more about the web manifest" and you will be in incognito mode when incognito is restricted via policy on ChromeOS. 
If you open a new tab from this incognito window, the new window will not have any policy restrictions. 

This is a big issue for students who want to bypass policy restrictions to browse freely on a school-issued Chromebook. 

What is the expected behavior?
Incognito mode will never open.

What went wrong?
In a GoGuardian & policy restricted ChromeOS Chromebook, the incognito mode can still be accessed through a chrome://inspect exploit. Please note that this is inconsistent and will only work once per boot from testing. If chrome://oobe/lock doesn't show up originally, it will show up after waiting on the page. 
If you open chrome://extensions while in the oobe/lock incognito window, it opens a new window with no policy restrictions or extensions. If you open chrome://settings or settings, it soft-bricks the chromebook and restarts it. The chrome://oobe/lock still pops up in chrome://inspect after.

Did this work before? No 

Chrome version: 64.0.3282.24  Channel: n/a
OS Version: 10.0
Flash Version: 28.0.0.133
 

Comment 1 by vsu...@google.com, Jan 10 2018

Components: Security

Comment 2 by cthomp@chromium.org, Jan 10 2018

This seems related to  https://crbug.com/795941 , although that had broader scope (the potential security concerns were deemed WontFix).
This bug was unintentionally fixed in another bug I reported, bug 795822

Comment 4 by 0spor...@gmail.com, Feb 8 2018

I believe I was the owner of the original bug, seeing posts on Chromebook support forum that kids are saying it's not working. Guessing it's fixed now. 

Would like a vague update on situation if possible.
I second that. 
I am the owner of a related bug that fixed this bug.

Sign in to add a comment