New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 806062 link

Starred by 2 users

Issue metadata

Status: Untriaged
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Feature



Sign in to add a comment

Flash and unsandboxed plugin access allowed on insecure HTTP sites

Reported by 93m4qau...@gmail.com, Jan 25 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.119 Safari/537.36

Steps to reproduce the problem:
1. Open an insecure HTTP site, e.g. http://www.userbenchmark.com/page/login
2. Click on the verbose chip, and then click on "Site settings".

What is the expected behavior?
Like location, camera, microphone, notifications, background sync, and MIDI devices, Flash and unsandboxed plugin access are blocked because the site is insecure.

What went wrong?
For some reason, Flash and unsandboxed plugin access are allowed on the site even though it is insecure HTTP.

Did this work before? N/A 

Chrome version: 64.0.3282.119  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: 

HSTS for the Entire Internet
 
Cc: emilyschechter@chromium.org est...@chromium.org
Components: Security Internals>Plugins>Flash
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam allpublic Type-Feature
Presently, this is working as intended, but locking down these permissions is a reasonable feature request, especially considering that Flash offers access to capabilities that are otherwise locked to HTTPS.
Labels: Needs-Triage-M64
Cc: susanjun...@techmahindra.com
Labels: FoundIn-66 Triaged-ET M-66 Target-66 OS-Linux OS-Mac
Status: Untriaged (was: Unconfirmed)
As per comment #1, as this is a Feature request to block Flash and unsandboxed on an insecure HTTP page, marking this as Untriaged for further updates from Dev.

Thanks..


Sign in to add a comment