New issue
Advanced search Search tips

Issue 819688 link

Starred by 1 user

Issue metadata

Status: Started
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug
Team-Accessibility



Sign in to add a comment

A11Y: Privacy bug: ChromeVox announces live regions on the lockscreen

Project Member Reported by dsexton@chromium.org, Mar 7 2018

Issue description

Chrome: 67.0.3363.0

Steps to repro:

# With ChromeVox running, visit http://oaa-accessibility.org/example/23/
# Click the 'Start' button
# Notice that ChromeVox speaks the live region updates
# Lock the chromeBook
# Notice that ChromeVox continues to announce live region changes

Expected: Live regions should not be announced on the lock screen

Actual: Live regions are announced at the lock screen
 
Cc: r...@chromium.org kerrnel@chromium.org tbarzic@chromium.org
Labels: Restrict-View-SecurityTeam
Owner: tnagel@chromium.org
tnagel@, can you PTAL? Is this a privacy bug?
Components: Privacy
That's an intriguing question. The behavior seems to be in line with audio (e.g. from a video that's currently being shown) continuing to play when the device is locked. (That may be questionable by itself, but when the website is a music player, it's probably what users expect to happen.)

Otoh, I'd consider ChromeVox output more akin to text on the page than to audio output of the page. Therefore my personal opinion is: Yes, it's a bug and we should fix it (similar as page contents rendering on the lock screen would be a bug).

I'll discuss among the privacy team and get back with a more authoritative answer.
Project Member

Comment 3 by sheriffbot@chromium.org, Mar 9 2018

Status: Assigned (was: Available)
Hi are there any updates on this bug?

Comment 5 by dtseng@chromium.org, Mar 13 2018

Cc: tnagel@chromium.org
Owner: dtseng@chromium.org
Status: started (was: Assigned)
I'll take a look.
Labels: Security_Severity-Low Security_Impact-Stable
Project Member

Comment 7 by sheriffbot@chromium.org, Mar 20 2018

Labels: -Pri-1 Pri-2
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam -Security_Severity-Low -Security_Impact-Stable Type-Bug
Any updates on this? I'm not sure it really is a security bug at this point.
I suppose it's more privacy.

If I have my Chromebook on and locked and someone messages me confidential info over hangouts and Chromevox shouts it out to who ever happens to be near by... That's no good.

Components: UI>Shell>LockScreen
Labels: -Pri-2 a11y-q2-18 Pri-1
Google Chrome	72.0.3593.0 (Official Build) dev (64-bit)
Firmware Version	Google_Caroline.7820.384.0

I've discovered another part of this bug - if you have focus on any Google Doc or Sheet, that will be read on the lockscreen, too. Live regions are part of the G-Suite backend. 

Steps: 
# Enable ChromeVox screen reader with ctrl + alt + z
# Open any Doc or sheet and place focus in the document area
# Navigate to the system tray with alt + shift + s
# Navigate to the "lock" button and invoke it
Expected: focus lands on the lockscreen 
Actual: focus remains on the Google Doc or Sheet and contents is read out loud 


Labels: a11y-LockScreen
Cc: mgalonsky@chromium.org
Labels: Hotlist-Privacy-Followup
The problem looks similar to issue 833870 -- maybe we should aim for a unified approach. Melissa, what's your take?

Sign in to add a comment