New issue
Advanced search Search tips

Issue 813062 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug-Security



Sign in to add a comment

Security: Canary 66.0.3349 loads file:/// urls

Project Member Reported by mar...@mwiacek.com, Feb 16 2018

Issue description

Please comment, if this is expected or whether this is mistake (which could potentially lead to security problems if something was not tested yet on this platform).

In previous builds: I wasn't able to access local files (see screenshot)

In 66.0.3349.0 file:/// urls are normally working
 
Screenshot_20180216-145345.png
162 KB View Download
Labels: Needs-Feedback
How specifically did you attempt to access this URL? Did you just type it in the omnibox, or did you click a link or interact with an app?

Comment 2 by mar...@mwiacek.com, Feb 16 2018

New Canary is saving offline pages as mhtml files in user disk space, when I deleted files, I got an error from Chrome and later based on it (with correct paths written in omnibox) I was able to see dir content and access single files.

Once again: earlier it didn't work for Android. 

Comment 3 Deleted

Owner: rsesek@chromium.org
Summary: Security: Canary 66.0.3349 loads file:/// urls (was: Security: latest Canary 66.0.3349.0 has got enabled file:/// urls, need clarification)
rsesek@ -- Do we expect any changes with regard to Android Chrome's access to file:///storage/ URLs? 
Components: -UI>Browser>Mobile -Mobile Internals>Sandbox

Comment 6 by rsesek@chromium.org, Feb 16 2018

On which previous version were you not able to load URLs?

Are you sure that you did not change the Android app-level permission to grant Chrome access to your files/media?

I don't think we've made any changes in this area.

Comment 7 by mar...@mwiacek.com, Feb 17 2018

Status: WontFix (was: Unconfirmed)
My bad, I'm sorry for taking your time.

Yes, it looks, that my permission was somehow revoked and that's why I had seen difference.

I'm closing this one.

Comment 8 by mar...@mwiacek.com, Feb 17 2018

Thank you.
Project Member

Comment 9 by sheriffbot@chromium.org, May 26 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment