Tom says: āIām still seeing an external PPAPI process when I open a PDF file, and only one process even when I have a mix of pdf from secure and insecure origins.ā So we have some risk of cross-origin PDF content. Consider https://internal.corp.example.com/q1-earnings.pdf and https://evil.com/evil.pdf. It would be better to do in-process PDFium in a site-appropriate renderer, or use different PPAPI processes per SiteInstance.
This is currently a gap in our Spectre mitigation plan, so it's probably Pri-1.
Comment 1 by infe...@chromium.org
, Feb 6 2018