New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 838674 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 23
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Chrome Extension update tab steals focus

Project Member Reported by iankm@google.com, May 1 2018

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://chromium.googlesource.com
/chromium/src/+/master/docs/security/faq.md

Please see the following link for instructions on filing security bugs:
https://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

VERSION
Chrome Version: 66.0.3359.117 (Official Build) (64-bit) + [stable, beta, or dev]
Operating System: [Please indicate OS, version, and service pack level]

REPRODUCTION CASE
Please include a demonstration of the security bug, such as an attached
HTML or binary file that reproduces the bug when loaded in Chrome. PLEASE
make the file as small as possible and remove any content not required to
demonstrate the bug.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace *with symbols*, registers,
exception record]
Client ID (if relevant): [see link above]



I recently went to switch from my corp profile to my personal profile on my work computer. When doing so, I was prompted to provide my password for my personal profile (expected). However, while doing to, a new tab opened and took focus to notify me of an updated Chrome extension (AdBlockPlus). Luckily I caught myself from continuing to type my password, but presumably any installed Chrome extension in focus could capture my keystrokes, right? If so, is there some way that we can prevent updated extension tabs from taking focus while the user is interacting with a page? 
 
Labels: -Type-Bug-Security Type-Bug
Summary: Chrome Extension update tab steals focus (was: Security: Chrome Extension update tab steals focus while entering password in Google sign-in )
See also https://bugs.chromium.org/p/chromium/issues/detail?id=367806

Labels: -Restrict-View-SecurityTeam
Labels: Needs-Triage-M66
Cc: sindhu.chelamcherla@chromium.org
Components: Platform>Extensions
Labels: TE-NeedsTriageFromHYD Triaged-ET
As per comment#0 this issue requires switch from corp profile to normal profile. Hence forwarding this to Inhouse team. Could someone from Inhouse team please have a look a t this issue.

Thanks!
Cc: sandeepkumars@chromium.org
Labels: -TE-NeedsTriageFromHYD Needs-Feedback
@iankm: Thanks for the report!!

Could you please confirm is this issue is as same as  issue 367806 ?

Thanks!!
Status: WontFix (was: Unconfirmed)
As there is no response from the reporter for more than one month.
Hence, closing the issue as wontFix.
Please feel free to raise a new issue if the issue is reproduced with latest chrome builds.
The latest chrome builds can be downloaded from the below URL:
https://www.chromium.org/getting-involved/dev-channel

Thanks...!!

Sign in to add a comment