Issue metadata
Sign in to add a comment
|
Security: Camera request permission UI spoof
Reported by
chromium...@gmail.com,
Mar 14 2018
|
||||||||||||||||||||||||||
Issue descriptionChrome Version: 67.0.3369.0 (Official Build) canary (64-bit) Operating System: All This is similar to bug 816033 , but in this issue the camera icon can appears after navigation to another origin. 1. Set up a local webserver to host poc.html 2. Click on "Click here" button and allow the request and wait. Actual: On the right of the omnibox, the camera icon is stays open, and when you click on it you can see the request is asking to "continue allowing http://localhost..."
,
Mar 14 2018
,
Mar 14 2018
,
Mar 14 2018
Thank you for providing more feedback. Adding the requester to the cc list. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 14 2018
Thanks for the video! I can reproduce this on Mac Canary. It doesn't reproduce on stable so it looks like a recent regression. I don't think this has security consequences because the user would have to already approve the permission prompt. At worst the user might get confused about which origin the menu represents, but I don't think there's a convincing attack scenario.
,
Mar 15 2018
Thanks for the video. I'm still having issues reproducing in Canary 67.0.3370.0 - estark, which Canary were you looking at?
,
Mar 15 2018
I'm reproducing on 67.0.3370.0. Maybe a race...? In which case, it might not be a recent regression as I hypothesized in #5.
,
Mar 15 2018
Able to reproduce the issue on Mac 10.13.3, Win-10 and Ubuntu 14.04 using chrome stable version #65.0.3325.162 and latest canary #67.0.3370.0. This is a non-regression issue as it is observed from M60 old builds. Hence, marking it as untriaged to get more inputs from dev team. Thanks...!!
,
Mar 18 2018
+timloh, do you have some time to investigate this?
,
Mar 19 2018
+cc mkwst, SYD isn't able to look at new permissions bugs right now unfortunately.
,
Mar 19 2018
,
Mar 20 2018
krajshree@: Can you reproduce reliably? If so, can you provide some extra details? I have been unable to repro on any platform following the instructions on the original post.
,
Mar 21 2018
,
Apr 18 2018
Making this bug available since I cannot reproduce and cannot act on it. I will gladly assist anyone who can provide actionable info.
,
Apr 18 2018
|
|||||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||||
Comment 1 by dominickn@chromium.org
, Mar 14 2018