Giving wrong information to end users about content in youtube
Reported by
mayankjo...@gmail.com,
May 17 2018
|
||
Issue descriptionVERSION Chrome Version: Version 66.0.3359.139 (Official Build) (64-bit) Operating System: [Please indicate OS, version, and service pack level] REPRODUCTION CASE steps to reproduce: step 1: use Chrome Version: Version 66.0.3359.139 (Official Build) (64-bit) Step 2 : go to URL youtube.com step 3 : open trending videos and play once. step 4 : now you can open any video in suggestion box the trending text will always remain same for all the videos until you refresh the page which will refresh this class : <a class="yt-simple-endpoint style-scope yt-formatted-string" href="/feed/trending">#2 ON TRENDING</a> Note: By this information viewer will get wrong information about the video. this issue is not reproducible in internet explorer as by clicking suggested video IE refresh the entire content. Possible fix for this issue: for chrome > what i understand you cached the information for trending box or only refresh specific frames in a page for fast processing but some how you missed this . we can link this object to name of the video which need to be refreshed for each video play, but again once we will do that that trending number will be always associated with that video only. Best fix: for youtube > i have come up with a idea to make a array of number of trending video +1. last one is for not trending and you call any such index depend upon the rank of video. another approach is to maintain a heap , of another possible candidate for trending one . Note : i have discussed the fix in terms of both Youtube and chrome
,
May 17 2018
I reported this issue as a non-security issue to Youtube. Thank you for the report.
,
May 17 2018
i need some understaning on this , i) how this issue is related to you-tube as this is not reproducible in IE or any other explorer , i can see whole page refreshing while clicking a new video, where in chrome i need to refresh the page go get correct information ? ii) this is non-security issue ? seriously , this bug is misleading the end customer with wrong information. i need a proper explanation on this . and how this bug is not got picked in early QA cycle .
,
May 18 2018
i am still waiting for my answer. or else i fill forward this mail-chain to higher management of google.
,
May 18 2018
You can forward this anywhere you like; it's a public bug in a public website that has been sent to the correct team. There's is not a security bug of any sort. You can learn more about security bugs here https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#TOC-Can-you-please-un-hide-old-security-bugs-
,
May 18 2018
my question remain same, how this bug is related to youtube not chrome? tell me if you are not going to answer me for this as well .
,
May 18 2018
The YouTube website decides what information it wants to show. The browser shows what it is sent.
,
May 19 2018
make sense to me but again: i) if this is the issue with Youtube and they decided to have same frame(trending box) for all other video , why this is not the case with other browser ? ii) and if youtube website decided to show that frame to all other videos, how come it resolve by refreshing the page in chrome ?
,
May 19 2018
one more thing i want to ask if you can share the information , what was the real cause of this issue ? and how you handled it . |
||
►
Sign in to add a comment |
||
Comment 1 by metzman@chromium.org
, May 17 2018Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Status: WontFix (was: Unconfirmed)