New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 906578 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Last visit > 30 days ago
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug



Sign in to add a comment

I can log into my Youtube account even though it is blocked through Youtube.tv

Reported by adria...@askerskolen.no, Nov 19

Issue description

UserAgent: Mozilla/5.0 (X11; CrOS x86_64 11021.56.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.76 Safari/537.36
Platform: 11021.56.0 (Official Build) stable-channel cyan

Steps to reproduce the problem:
1. Go to youtube.tv
2. Click on "Already a member"
3. Choose the account and open a new tab with youtube

What is the expected behavior?
You will be logged into youtube even though you are supposed to be blocked from this action by the administrator.

What went wrong?
I was able to bypass the block and logged into youtube

Did this work before? Yes Up to date

Chrome version: 70.0.3538.76.  Channel: stable
OS Version: 11021.56.0
Flash Version: 31.0.0.122
 
Google bug report.pdf
68.6 KB Download
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Owner: dskaram@chromium.org
This looks like an enterprise policy bypass rather than a platform security bug.
Cc: allenwebb@google.com
Components: Enterprise
Labels: Needs-Feedback
Thanks for reporting this!

Could you please provide URLBlacklist policy example from chrome://policy page? Have you tried to block youtube.tv using https://tv.youtube.com and this does not work?
Status: Assigned (was: Unconfirmed)
This issue has an owner, a component and a priority, but is still listed as untriaged or unconfirmed. By definition, this bug is triaged. Changing status to "assigned". Please reach out to me if you disagree with how I've done this.

Sign in to add a comment