New issue
Advanced search Search tips

Issue 884432 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Sep 21
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac
Pri: 1
Type: Bug-Security



Sign in to add a comment

Address bar is hidden even after exit from full screen

Reported by s.h.h.n....@gmail.com, Sep 15

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.92 Safari/537.36

Steps to reproduce the problem:
1. Make sure that your window is maximized
2. Go to https://test.shhnjk.com/FS.html
3. Click on link
4. Press Esc key

What is the expected behavior?
Address bar is visible

What went wrong?
Address bar is not visible

Did this work before? N/A 

Chrome version: 71  Channel: dev
OS Version: OS X 10.13.6
Flash Version: 

No repro in Windows
 
Better PoC: https://test.shhnjk.com/FS_spoof.html
FS_spoof.mp4
193 KB View Download
Components: Blink>Fullscreen
Labels: -Pri-2 Security_Severity-High Security_Impact-Head OS-Android OS-Chrome OS-Linux OS-Windows Pri-1
Owner: foolip@chromium.org
Status: Assigned (was: Unconfirmed)
foolip: Are you a good owner for this, or know anyone else who might be? Feel free to assign it back to me if not.
Project Member

Comment 3 by sheriffbot@chromium.org, Sep 19

Labels: Target-71 M-71
Project Member

Comment 4 by sheriffbot@chromium.org, Sep 19

Labels: ReleaseBlock-Stable
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it.

If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: foolip@chromium.org
Owner: dtapu...@chromium.org
dtapuska@, can you diagnose this, see if it's a regression from recent changes?
Cc: mbarbella@google.com
mbarbella@ were you able to reproduce this? I cannot. I've tried both in Chrome Dev 71.0.3554.0 (on Mac OS 10.13.6) and on Linux.
Cc: -mbarbella@google.com mbarbe...@chromium.org
Labels: Needs-Feedback
I'm actually also unable to repro in a a recent build.

s.h.h.n.j.k: Could you confirm that it still reproduces in a revision after the one mentioned in c#6? Are there any other factors that might make this difficult to repro if so?
Hmm, I can't repro anymore as well. Maybe fixed in recent version :(
Status: WontFix (was: Assigned)
Not reproducible anymore. 
I can repro this now in stable Chrome 70. Is it only my Mac issue? or anyone else can repro? I can't repro this in Canary though
https://test.shhnjk.com/FS_spoof.html
Project Member

Comment 11 by sheriffbot@chromium.org, Dec 28

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment