New issue
Advanced search Search tips

Issue 851663 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 845612
Owner: ----
Closed: Jun 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 1
Type: Bug
Proj-Servicification



Sign in to add a comment

NetworkService supports uploads of type TYPE_FILE without any protection.

Project Member Reported by mmenke@chromium.org, Jun 11 2018

Issue description

This basically allows a compromised renderer to upload an arbitrary file that Chrome has access to and the attacker knows the path of.  This seems concerning enough that we shouldn't go to Canary until we have some sort of protection in place.
 

Comment 1 by mmenke@chromium.org, Jun 14 2018

Mergedinto: 845612
Status: Duplicate (was: Untriaged)

Sign in to add a comment