Webpage screenshot can be watched, even if it was opened in incognito mode and its tab and Google Chrome are already closed!
Reported by
fed...@gmail.com,
May 29 2018
|
||||||||||||||||
Issue descriptionChrome Version (from "Settings > About Google Chrome"): 66.0.3359.122 Device Type: iPhone 7 PLUS 128GB Black URLs (if applicable): any fullscreen video e.g. https://www.youtube.com/watch?v=G3NXNnoGr3Y Behavior in Safari (if applicable): in Sarafy browser on iOS the bug is not applicable (a blank white screenshot appear instead) Steps to reproduce: (1) Screen auto-rotation should be enabled (2) Turn the device to portrait view (3) Open Google Chrome (4) Add new incognito tab (5) Open webpage with a video e.g. https://www.youtube.com/watch?v=G3NXNnoGr3Y (6) Play video in fullscreen mode (7) Turn the device to landscape view (8) Hide the app (tap the Home button once) (9) Turn the device to portrait view (10) Open the app (IMPORTANT: tap the icon; if double tap the Home button and choose the app from the list of running apps - the bug won't appear) (11) Close the incognito tab (12) Close the app completely (double-tap the Home button and swipe) (13) Open the app (14) Hide the app (tap the Home button once) (15) Turn the device to landscape view (16) Open the list of all running apps (double tap the Home button) (17) You can see a preview screenshot of already closed incognito tab Expected result: A blank preview screenshot should be presented as in Safari Actual result: You can see a preview screenshot of already closed incognito tab The bug will also appear if you switch all landscape/portrait instructions. In such case the buggy screenshot will be in portrait mode. This bug can be very confusing in some cases ;) Please keep our privacy even from those who have an access to our devices. I hope to get i reward for this bug :)
,
May 29 2018
,
May 29 2018
Probably related to issue 679663 . That bug's owner, lpromero@, left the team. iOS folks, can you please triage?
,
May 30 2018
For a typical webpage there is no bug now. Current problem only occurs when fullscreen video was opened.
,
Jun 15 2018
,
Jun 15 2018
srikanthg@ can you confirm?
,
Jul 17
I can reproduce this with latest M69 on iPhone7 plus device.
,
Jul 17
This is reproducible on all devices. New set of steps for easy repro: (form Justin) 1. Launch Google Chrome 2. Open Incognito tab 3. Open youtube.com and play any video in fullscreen mode 4. Background the app. 5. Double click Home button to bring up App Switcher. Actual Result: Video snapshot is displayed. Expected Result: Chrome splash screen should be displayed masking the contents of the incognito. Doesn't reproduce on Safari. Reproduces on Firefox private tabs as well. Tested on iPhone7plus, iOS10.3.3 and iPhoneX iOS12.0 Its currently marked for RBS M70, please prioritize.
,
Jul 17
ghendel/mardini@ WDYT for priority/milestone?
,
Jul 18
,
Aug 2
Could somebody answer when and how I will recieve a reward according to Chrome Reward Program?
,
Aug 2
I think as you have not used the template for security bugs, this is not monitored by the VRP team (and I very much suspect that it would be considered a security bug as it's mostly privacy related). awhalley@, Could you please check?
,
Aug 2
Hi fedoit@ - thanks for reporting the bug! I'm afraid, however, that this isn't covered under the VRP. Please see: https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#What-are-the-security-and-privacy-guarantees-of-Incognito-mode and https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Are-privacy-issues-considered-security-bugs Cheers!
,
Sep 3
Confirmed that this is a bug and should be a P2. Changing the label to M71 (would be good to have a fix soon) and assigning to justincohen@ who can reassign if this should go to someone else.
,
Sep 3
,
Sep 6
,
Nov 4
,
Nov 5
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/7cbae5d129b4ae71337cd24d1fb5ebfcdb5c70e4 commit 7cbae5d129b4ae71337cd24d1fb5ebfcdb5c70e4 Author: Justin Cohen <justincohen@google.com> Date: Mon Nov 05 15:28:23 2018 Use the shared application window for the incognito overlay. Allows the incognito overlay to appear for system overlays like fullscreen videos. Bug: 847414 Change-Id: I0594535d0e2a1667c77faf01da88d502f19aa67f Reviewed-on: https://chromium-review.googlesource.com/c/1316598 Reviewed-by: Peter Lee <pkl@chromium.org> Reviewed-by: Olivier Robin <olivierrobin@chromium.org> Commit-Queue: Justin Cohen <justincohen@chromium.org> Cr-Commit-Position: refs/heads/master@{#605337} [modify] https://crrev.com/7cbae5d129b4ae71337cd24d1fb5ebfcdb5c70e4/ios/chrome/app/application_delegate/app_state.mm [modify] https://crrev.com/7cbae5d129b4ae71337cd24d1fb5ebfcdb5c70e4/ios/chrome/app/application_delegate/app_state_unittest.mm
,
Nov 5
,
Nov 12
Reopening Version: Chrome Beta 71.0.3578.49 Device: iPhone 8 iOS: 12.1 Video snapshot is displayed https://drive.google.com/open?id=1FgzCK8Xxd0iq1UYMv4djmi3V6pB0Fs6U
,
Nov 12
This is fixed on M72. I do not think this needs to be cherry-picked to M71. |
||||||||||||||||
►
Sign in to add a comment |
||||||||||||||||
Comment 1 by e...@chromium.org
, May 29 2018