In order to prevent malicious RP from hijacking response from the authenticator, always check RP id hash received from the authenticator with rp id of the requested RP.
Your change meets the bar and is auto-approved for M67. Please go ahead and merge the CL to branch 3396 manually. Please contact milestone owner if you have questions.
Owners: cmasso@(Android), cmasso@(iOS), kbleicher@(ChromeOS), govind@(Desktop)
For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Comment 1 by hongjunchoi@chromium.org
, Apr 5 2018