New issue
Advanced search Search tips

Issue 869363 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 31
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Security



Sign in to add a comment

Security:dialog in fullscreen may lead to UI spoof

Reported by zxyrz...@gmail.com, Jul 31

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.75 Safari/537.36

Steps to reproduce the problem:
Go to http://test.au1ge.xyz/dialog.html and click start

What is the expected behavior?

What went wrong?
Maybe consider call dialog.showModal() in fullscreen should kick out fullscreen

Did this work before? N/A 

Chrome version: 68.0.3440.75  Channel: stable
OS Version: OS X 10.13.6
Flash Version: Shockwave Flash 30.0 r0
 

Comment 1 Deleted

Sorry I don't think this is a security issue right now, please close this issue.
Status: WontFix (was: Unconfirmed)
WontFix as per c#2.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 7

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment