Issue metadata
Sign in to add a comment
|
NetworkService supports uploads of type TYPE_FILE without any protection. |
||||||||||||||||||||||||
Issue descriptionThis basically allows a compromised renderer to upload an arbitrary file that Chrome has access to and the attacker knows the path of. This seems concerning enough that we shouldn't go to Canary until we have some sort of protection in place. |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by mmenke@chromium.org
, Jun 14 2018Status: Duplicate (was: Untriaged)