New issue
Advanced search Search tips

Issue 873659 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Aug 24
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug-Security



Sign in to add a comment

Bug #806162 bypass using iframe

Reported by nikhil.m...@gmail.com, Aug 13

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36

Steps to reproduce the problem:
1. Host attached files on server
2. run exploit.html
3. You will see behaviour happening in  bug #806162  

What is the expected behavior?
As soon as full screen is requested chrome switched it back to main window. 

What went wrong?
As the full screen is requested it remain same without displaying any origin, warnings etc or switching back to main window. 

Did this work before? No 

Chrome version: 68.0.3440.106  Channel: stable
OS Version: OS X 10.13.6
Flash Version: 

It worked for me on latest stable versions 
- MacOS 
- Windows
- Android
 
test.html
309 bytes View Download
exploit.html
49 bytes View Download
evil.html
36 bytes View Download
Components: UI>Browser>FullScreen
Labels: Security_Severity-Medium M-70 Security_Impact-Stable
Owner: spqc...@chromium.org
Status: Assigned (was: Unconfirmed)
spqchan@, could you help triage this one? (since you were the owner of  bug #806162 ?  
Please feel free to re-assign. Thanks!
Project Member

Comment 2 by sheriffbot@chromium.org, Aug 14

Labels: -Pri-2 Pri-1
Hi any initial updates here? or it will take more time to triage the issue?
I am swamped right now but I'll work on this issue once I have the time
Owner: sdy@chromium.org
Thinking about this, I won't get the chance to look at this anytime soon. sdy@ can you PTAL? If not, let me know 
Blocking: 640466
Blocking: -640466
Cc: sdy@chromium.org
Owner: a...@chromium.org
Over to avi@, who owns this area.
Status: WontFix (was: Assigned)
 Bug 806162  was about successfully using a dialog to interfere with the "press esc to exit fullscreen" bubble. This bug does nothing of the sort. It is an example of how to use fullscreen, and while it happens to use an iframe, everything here is working as designed.
I Reported it since the fullscreen remain same instead of switching back to main window again. which you can see by directly opening test.html 
If the main frame navigates, we drop fullscreen, with the understanding that it is a different site and therefore should not inherit the fullscreen of the previous site. Because you aren't changing the main frame, we leave fullscreen alone, with the understanding that sites may need to change around various parts of their page.

This is intentional behavior and explains what you are seeing.
Also note that in  bug 806162 , we drop fullscreen as a defensive security measure because it seems like the page is trying to evade the fullscreen bubble. In this case, we drop fullscreen not as a security measure, but because the next page is not expecting to start in fullscreen and might act weirdly.

Because this particular drop is not for security reasons, we have leeway to not do it when it seems like the page is reasonably expecting to remain in fullscreen.
Thanks for the explanation. 
Project Member

Comment 13 by sheriffbot@chromium.org, Dec 1

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment