New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 863194 link

Starred by 3 users

Issue metadata

Status: Fixed
Owner:
Closed: Jul 23
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 1
Type: Bug



Sign in to add a comment

[Omnibox] verify that images are not processed in the browser process

Project Member Reported by dschuyler@chromium.org, Jul 12

Issue description

Labels: Restrict-View-SecurityTeam
Adding Restrict-View-SecurityTeam in case there's a vulnerability being discussed here.
Components: UI>Browser>Omnibox>AiS
Owner: ----
Owner: jdonnelly@chromium.org
Owner: tommycli@chromium.org
I believe that the images that are being shown in the omnibox suggestions are being safely decoded, *not* in the browser process.

The images in question include both the existing weather images shown with Answers in Suggest and the new entity suggestion images. Both are handled by the following service:

chrome/browser/bitmap_fetcher/bitmap_fetcher_service.h

BitmapFetcherService used ImageDecoder (chrome/browser/image_decoder.h), whose header states, "This is a helper class for decoding images safely in a sandboxed service."
Cc: -jdonnelly@chromium.org
Owner: jdonnelly@chromium.org
Status: Fixed (was: Assigned)
If anyone has additional questions, feel free to reopen this issue.
Project Member

Comment 6 by sheriffbot@chromium.org, Jul 24

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 7 by sheriffbot@chromium.org, Oct 30

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment