New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 799763 link

Starred by 5 users

Issue metadata

Status: Duplicate
Merged: issue 691799
Owner: ----
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Bug
Team-Security-UX



Sign in to add a comment

Local data:image/ URLs are considered "Not secure" by the verbose chip and Developer Tools Security tab

Reported by 93m4qau...@gmail.com, Jan 7 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36

Steps to reproduce the problem:
1. Open data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEAAAABACAYAAACqaXHeAAAN+UlEQVR4Ae2aBXTjyNJGb7UkU+LEk2Fahoezs8zwmJmZmZmZmZmZmZnfzDIzMwwkQyapu37Fcp+Js45jJ9l9P91zvtMlt5LMV1VqqeXh/zj/j3C7ovKEt1xaHh4plAulKDI2DgGqsU3ipmk2qo2d33rb/jsAvR0ToNxW3OelF67MlXL3Qe3dxcnhiSR7Q5SPreIcqGoqMCKIUYJAEGfrgcoVLjKnEsufq9XG74GbuI2QE59/HgtJVC6OFoL4CaI8USU4ut50LbNML6t2DKgqHh+KQCFnVU34r9DxTVeT7wDbWUDkvi+6hIWglm+uKBfzr0XdMxt1htQbaY8e7Z6AjiRolzkB8nm7A40+V6vzfmATC4AcN88EVMaGSkFSfWsSJy9quqAAoHQa6Wpq6tzsCehIWD6SamDMh66o67uABvNA9ptHAu5U1AdoJJ9uxOyhCijMOwEDdEwpp1dggucCf2COyL1fPXgCGsXrw9FkxUesNS+ME1ARoCMBHcZnr+rgCfDn5MJETZR//9iV+70BsAyIPOpRyiDsWHHp0lxZf9VousNVQcWA3PqGouhtmoDO85RiLvhHvVp/CDA+2BrwvHPol2Ipt3c+dH9oxrovIiggYnDZ+B9LgLaDYk7OrzX03sAN9Ikc84IL+zMfxfsUI/1nIwlWCoKKgIAgODGIACr/yQT4BfIqq+4Y4Eb6wASRMpuGbGNZLpA/NGJZiXpzzhtFUFS1w/xtjSpdacS6V0jw+2o1P5qK2WRmP+kfUaFkfhMnbh9vTrMAVUXJRqEV0DfKbUY9dncZGUp+us/4PkEqesnMdsKS0mGfqsb2EHWKU4WWQAEB/DHO111nrdLtkaN60520afWlb01FL8lJL72EmRiKq/dpBu63zgkYAIMIaGtUwIAA7QVQjEEBRGChngR73gZ9rF1/tzGJGo3uCfyZGTA2cXTTkqUrlq7aM/dtax3qS66KOhBVVMH3gWo2or4L/HwnuvCt4M13xbpQVOPPbrk5yaWim8xME2PLk1/ll64dK0gd1LXNKdAetR2pIqlAcarIrarTnyFvZKFzlBDuv3R1+JpUdJOc+NKLmM7q/RatX1Iun+lUaGy5losv3ESYzyMSsPv+L2gqmRSCQxAjgJAhIHLr9neWSglWjYWUchKPlmrj1e1w87ZGPL5TY7+2qBPtuBT8aEQjAyqi4BHUKiC+9xUcikEAlSCpRcHdu90aw0LJMZ1yWPiKUwGgsHgtY+VNjO9sEOQKU34piAIIDs0SotpeC6TdJX4tcKyqCPc4ZIgTDhpm1ZI8bSJgGW22jDc479IJTjt3nK07mggCgYEs4S2ZQBAMGJ98MGJAQIy0YhEIQoOKwbQLVTTmdcCLmYZ84KtXMpVzJpbvUSknV7kgEjy1Cc495RIkjLIkGAGV3QuiATCo74IW0tKiYeWJ9xjlPkdUBmrnsy+Z4E8bN1OtOyT7valMyzRksQkEAxhjWiIIMEYwgUEQUMA/sEmyo2D2WAXsZAphsbQXU8nVtr/PBTlhKsUKK1eVueGGnUADk8vtNiwKatCpXdC+KA7aJ8erHrucynCIZ6IK51wLV22BbVVajBRhryVw0FqolECA9QdU2H9tmZ/+5RauuaWRmRWDfwoNo4Bg0nCqIMw+z5KTmRY/is9DrmzY+ljgix0JMNHWzgQU8g9AyRA8LN57PzZvPps4TnCxILkICEDbC6GhbV5BDMffucArH7eCoN0R122FH5wKp16puBkWSRE4Yh/hMYfD6jEYKgY87n4r+MXfN3PFjUnLaBBFhEGAiDfoR8Ffm/jCGx8LoDjDE6YnQD75qy14/n29WT+WK5ypSld23HwdV158I0iAhAEmyoOIr0o7hoP3y/O2p69umVfgl2fCd09RnOtxL2c3gcATjoIHrMfDLzfs5ObtndX1exH/WXaMT4q36JOB0cTVw7FlgDeN0dwivEoufK5TULpTXrGGoeEcoGAtNmmiTnHsfkIcG4ZXPW6lN89X/wHf3thpvicK1sHX/w1f/Sce7nHoEMWcYIzJ2j4wrU4IwzRuX/fGCEFosuKkY+DPmzw2ARLmTd7sukcqvEzHgcg9aKPdpLBmv7WQWUasQ20TdPcu4Sn3GWN0KIB25X9/nnZWeZbqexT49Tnwq7PxW10O3T9qm2obTiWGltkwM9qaT+OWYTN5HGXmgyBLSBREJ6XCy0w9QHSNKj3JjYyxZPkoiGSWrUPjZpacxcI9D1/kr/m07Qc0r9yKb25QbpxQAA5YnaNc0papsGVI2glpVTxVezRZZ7TOmTTv54JURg9LhfHywdNOzJswar/U1E5NZ9meaxF1qFNAcFjUWu7rb3VkC55zczDfGZJY+N6puxe2/ZYHGGlXv23eVzfMxsysaSXCn9c6FiMk1h2YCi/jg+f/gGWqQjdUO2VyRVbuubzdBe37tEs4+k5D/lbXWu11nub9o+DGy5QddVqsWWIQAdMyPLW6JlW73Y3xhhHp9BSF0YihVEhFSz5oVrcuZgAWrVpJPh9mpixUyiGrlhWA7D7vFJjVfH+bnMRN/s7seNGwoZTPKu9Ne8Mgfe0RciHFVEzK+CCKgwIDICZg9d5r8cvfmqU5PFdtGcD8rIthxhWb8DAyJJ3VHRBrNErFpIwPrHNFBbz6YXhxhfLoEDoZl0I8/glPdQDzPXaG/rLyhAHT6X/7rRAqYZiNGB9MR/uQA1btuxZRQKTzZ7XHP0b7M6+3w1faxgeBMTVfsUHIFYssXb2Y7btiPKPFmbz6gwHNa7ZH8MRubtX3JEKSikkZH+xSW6eN6mBatmYVN43HePZa0mF83uYB9l2Kh2p9fm9NAidxKiZlfDBcGdsCypwIA/KVJdy0pQlkuzojvVt+EPOhgXV7CADba0o9kTlV39NMqKViUsYHn34Ut6gq0KneKF6jy5ew8YKdAFRK2a4O7VX12c17jtoPhvO0uGGrgBhvfuDqN2y8PaFaT8WkjA++8NeqixtJfbDlsPO0s28s+H9Ua0sbmJ5V78t8GMBjjgRv+NpxQy90lg9zRi5OhZeZeqAmuGYuC6FqpvGkxClXNGsAq8eyLa32rPrs+4GnHAsrRwWAS66vje+MzZxbXwGn5uRUeJmpB6j+eQ4LYQe/OTdX3NUAVW3t5++/rnfVe5l/0Hq47zoBYNsuy6U3MQoyp9b3KPYvqfAyUw+qEn9WVZkPE1X41kZQMp563GQVlcD0qHqXtn/GCfDk4wQBEuv410UxcTBiVPEMXH2NG87min9NhZd84d+OqWw4c9e2MB+MME8O31t53JEgQot0S9va1W24TLEO6L7apwteds37tk+s8u0/b6OybGkaD2heO0PXdL8D7ssUwrDaZCqxTX4REjxhvt/annKFsKuhPP5oGMrByorw0nvBM46X1sbmik1Zt/i7xr5Ls1udX+2ztnd88TfbWLO6Mk/zPnDfYBrylT9Umcq/rtQ1msTXmCgnTEGk0+TseHPZtXzInopI/0n854V1frqhxkhRWH+npVg3P/Mujrc2R0trgQ7D8rnTlOn8e8P203KF6NCF+ppKgBUVOGofuPNqZWmZrtw07jj76oR/X9Dkhq0JtlnnwSetxmH6M9/ji9cktm8D3so0wnBbnenslOpTRnX4vECCgc12Q1trAPzkDPj5WUK5QCsJpYgW1RhumbBs3lrDqqCJw1rLugNGUDGgA5vvwDXiHYVC6WN0Qb71D6Ubvz1z4l/5Yv4Y5k9fGxfXbGKbMWotSSqxTR5y4ipilcHNd4bETfda4H10wdQaDbqpWNX7W1tPFs54ppl2xc45QLE4VB3HHlRZEPNJI77QVvIfTkU3mZkmDr3nom3xDt6mzs3bdC/jHqcOq4o6ZbTkWLyoNG/zLm46iaLnRDvjOBXdZHzQTXc/fPid9Ub99EENe0Fv4x5nLTgFVVziOPouS0iczMu8quKMeatq8o9UzCTjg5nUXLH4mCS22wd9JPaoV49JVYeirUTsvSIkX4j89MDmPbbZ+P01JxXflYpeMrOdcKdH0Uwmxg+NbaNBn6hXn5MaJ2hi0ThOV/4xrPPTczNfj5MztTj8yLX/UpeKXjI+6KWTTlhzmW0kxydxPRlskzx7/6tzuMTiVDnkwDJOZPaq9zCfNJqXlbVwv1KdHamYTcYHs+kBd1l8ahLbYxpxo6GDtoHOPOXUkjhH4CxrVw2jOsjOrpNmIz6rKKXjgJvpE0PfZEkItk/cobmzuR3tYVb7KJ6vfhyDsxyzbsQvfF3p/UoN6rX6H6RYPKFa4OZU9Cvjg351/PF7XtVYM7q0Wa2fotaCzn09UHVYq1SGlbFKcU4t75oNFzeTN99w7/J9rz1WdqRiEMlbVJkrl35wy+s04G3FUjFCBKV/1FpcktCs1bnfERUkDGDAt8jNnfFFpmCeA/ydOWLW/rnGXHX3Q0rvKTfN0lq99g+bNOkbVTSVtTH7LA8IcwHQ/1vkpN7cYZvx63T50Do7Wvx7KuYovxucP//csOmAxOk3Iw0PCwpFQZgR166+re3iAccuxap4pzM2gSrEtfo4QfDxUraxGWf++M3QwvGLi3YuN7tq74foIVEUjJogBOn8v/3OJq0EHLRHwMplJdR1N64KSb3qLOZPiPkGY0M/AqosIIN3wKBdkcgLE0nuk5PcWmNdgcCIc4pJmpx0RMmGFANVhVTWORqx3SGil4aB2ejU/NkMFf8CbOW2wb8TvP34zi/OW56LWV4OzMiKkebWiNCVlyyu5sJyrTA8sROocXvyoe9d839Z/5+A/wIa87S6ygZS+QAAAABJRU5ErkJggg==
2. Click on the verbose chip..."Your connection to this site is not secure".
3. Press Ctrl+Shift+I to open Developer Tools, and then click on the Security tab..."This page is not secure".

What is the expected behavior?
Local data:image/ URLs are considered secure since they are locally loaded and not transmitted over the Internet.

What went wrong?
Local data:image/ URLs are considered insecure by both the verbose chip and the Developer Tools Security tab even though they are locally loaded and not transmitted over the Internet.

Did this work before? N/A 

Chrome version: 63.0.3239.132  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version:
 
Labels: Needs-Triage-M63
Components: -UI Internals>Network
Cc: sc00335...@techmahindra.com
Labels: Triaged-ET M-65 OS-Linux OS-Mac
Status: Untriaged (was: Unconfirmed)
Able to reproduce this issue on reported version 63.0.3239.132, on latest canary 65.0.3315.0 using windows7,Ubuntu 14.04 and Mac 10.13.1 with given URL in comment#0

This issue is seen from M50[50.2661.0]. Hence considering this issue as Non-regression and marking as Untriaged.
Components: -Internals>Network UI>Browser>Bubbles>PageInfo
I know that we're considering not allowing direct main-frame navigation to data URLs (and that may have landed recently).

Is this causing a mixed-content warning or not-secure status on an otherwise secure page, or is this only happening on direct navigations?

Comment 6 Deleted

To clarify slightly, we're looking into disallowing _page-initiated_ navigations (see  https://crbug.com/594215 )
Only when navigating to it directly
 Issue 800158  has been merged into this issue.
Cc: est...@chromium.org
Components: UI>Browser>Omnibox>SecurityIndicators>VerboseChip
Status: Available (was: Untriaged)
estark - this looks like one for you too (sorry for all the bugs)
Mergedinto: 691799
Status: Duplicate (was: Available)

Sign in to add a comment