In a GoGuardian & policy restricted ChromeOS Chromebook, the incognito mode can still be accessed through a chrome://inspect exploit.
Reported by
jeremyeb...@gmail.com,
Dec 16 2017
|
|
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36 Platform: 64.0.3282.24 Steps to reproduce the problem: Go to chrome://inspect/#other. Find chrome://oobe/lock Click on "inspect" and navigate to "application" on the top bar. Click on "read more about the web manifest" and you will be in incognito mode when incognito is restricted via policy on ChromeOS. If you open a new tab from this incognito window, the new window will not have any policy restrictions. This is a big issue for students who want to bypass policy restrictions to browse freely on a school-issued Chromebook. What is the expected behavior? Incognito mode will never open. What went wrong? In a GoGuardian & policy restricted ChromeOS Chromebook, the incognito mode can still be accessed through a chrome://inspect exploit. Please note that this is inconsistent and will only work once per boot from testing. If chrome://oobe/lock doesn't show up originally, it will show up after waiting on the page. If you open chrome://extensions while in the oobe/lock incognito window, it opens a new window with no policy restrictions or extensions. If you open chrome://settings or settings, it soft-bricks the chromebook and restarts it. The chrome://oobe/lock still pops up in chrome://inspect after. Did this work before? No Chrome version: 64.0.3282.24 Channel: n/a OS Version: 10.0 Flash Version: 28.0.0.133
,
Jan 10 2018
This seems related to https://crbug.com/795941 , although that had broader scope (the potential security concerns were deemed WontFix).
,
Jan 10 2018
This bug was unintentionally fixed in another bug I reported, bug 795822
,
Feb 8 2018
I believe I was the owner of the original bug, seeing posts on Chromebook support forum that kids are saying it's not working. Guessing it's fixed now. Would like a vague update on situation if possible.
,
Feb 8 2018
I second that.
,
Feb 8 2018
I am the owner of a related bug that fixed this bug. |
|
►
Sign in to add a comment |
|
Comment 1 by vsu...@google.com
, Jan 10 2018